About

The consultancy born at the intersection of behavioral economics and human experience.

NOW HIRING

Join a team reshaping how the world experiences brands.

View open roles →

COMPANY

GROW WITH US

CONNECT

Services

Comprehensive CX and management consulting for enterprise brands.

ALL SERVICES

Explore the full range of CX & management consulting services.

Browse all services →

CORE

SPECIALIST

Solutions

Structured solutions that turn CX ambition into measurable outcomes.

ALL SOLUTIONS

Explore every CX solution we offer.

Browse solutions →

STRATEGY & GOVERNANCE

DESIGN & DELIVERY

CULTURE & EXPERIENCE

Industries

A decade of CX transformation across the region's defining sectors.

ALL INDUSTRIES

See how we work across every sector.

Browse industries →

BUILT ENVIRONMENT

FINANCE & TECH

PEOPLE & MOBILITY

Products

Proprietary tools, platforms, and AI that power CX transformation.

ALL PRODUCTS

Explore the full Renascence product ecosystem.

Browse products →

AI & TECHNOLOGY

LEARNING & GAMES

PLATFORMS & TOOLS

AI PRODUCTS

Opinion

Insights, research, and conversations at the frontier of CX.

ReadExperience JournalArticles & research on CX, behavior, and transformation.Watch & listenExperience LoomOur video podcast on CX & behavior.CuratedCX NewsIndustry news that matters in CX, minus the noise.

Latest articles

Latest episodes

Latest news

Hub

Free tools, templates, and resources to advance your CX practice.

NEW · MANIFESTO

Burn the Deck. Ten Virtues. Zero Excuses. — read our manifesto for the brave consultant.

Start reading →

AI TOOLS

FREE TOOLS

LEARNING

CULTURE

Banking · 15 September 2026

Revolut confirms data breach after fake government email scam

Revolut disclosed customer data, including passport details, after staff mistook a fraudulent request sent from a spoofed government email domain for a genuine official inquiry.

Newsdesk
Curated briefing · 2 min read

What happened

Revolut has confirmed a data breach after staff responded to fraudulent requests that appeared to come from a legitimate government agency email domain, disclosing sensitive customer information including passport details. The digital bank has acknowledged the incident, which stemmed from what looks to be a social-engineering attack rather than a technical system breach.

According to Finextra's reporting, the requests were sent using an authentic government email address, lending them a degree of credibility that led Revolut employees to release customer data believing the inquiries were genuine official business.

Why it matters

The incident is a reminder that many of the costliest data-security failures now originate in process and judgement rather than in code. Attackers increasingly target the human and procedural layer — impersonating trusted institutions to extract information that firewalls and encryption cannot stop — and a fintech handling passports, financial records and other high-sensitivity data is a natural target for this approach.

For experience and risk leaders, the case underlines that verification protocols for "official" requests need to be as rigorously designed as any customer-facing journey. A single point of human discretion, exercised under the appearance of legitimate authority, was apparently enough to expose regulated personal data — a vulnerability that governance frameworks and staff training are meant to close.

The Renascence take

Breaches like this are rarely a technology story; they are a service-design and decision-architecture story. The failure point sits at the moment a frontline or back-office employee must decide, in real time, whether a request is genuine — and that decision was made easier to get wrong by the appearance of official credibility.

Most coverage of this incident will focus on cybersecurity hygiene, but the real lesson is behavioral: authority cues — an official-looking domain, formal language, urgency — reliably override caution, even at sophisticated, highly regulated institutions. A customer-obsessed operator should treat data-release requests the same way it treats high-value transactions: with mandatory friction, independent verification through a second channel, and a default posture of scepticism regardless of how credible the sender appears. Trust, once extended to a domain name instead of a verified process, becomes the vulnerability itself.

Sources

This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.

FAQ

Questions we get on this topic

Staff at Revolut disclosed sensitive customer information, including passport details, after receiving fraudulent requests that appeared to come from a legitimate government agency email address. It was a social-engineering attack, not a technical hack of Revolut's systems.

According to Finextra's reporting, the breach involved sensitive customer information including passport details, released by employees who believed the requests were genuine official business.

No. Revolut has acknowledged the incident stemmed from employees being deceived by fraudulent emails that mimicked an authentic government domain, rather than from a breach of its technical infrastructure.

It highlights that verification of 'official' data requests needs the same rigour as customer-facing security processes, since attackers are increasingly exploiting human judgement and perceived authority rather than technical vulnerabilities.

Stay ahead of CX

Get the signal, not the noise.

The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.