Banking · 15 September 2026
Revolut confirms data breach after fake government email scam
Revolut disclosed customer data, including passport details, after staff mistook a fraudulent request sent from a spoofed government email domain for a genuine official inquiry.
What happened
Revolut has confirmed a data breach after staff responded to fraudulent requests that appeared to come from a legitimate government agency email domain, disclosing sensitive customer information including passport details. The digital bank has acknowledged the incident, which stemmed from what looks to be a social-engineering attack rather than a technical system breach.
According to Finextra's reporting, the requests were sent using an authentic government email address, lending them a degree of credibility that led Revolut employees to release customer data believing the inquiries were genuine official business.
Why it matters
The incident is a reminder that many of the costliest data-security failures now originate in process and judgement rather than in code. Attackers increasingly target the human and procedural layer — impersonating trusted institutions to extract information that firewalls and encryption cannot stop — and a fintech handling passports, financial records and other high-sensitivity data is a natural target for this approach.
For experience and risk leaders, the case underlines that verification protocols for "official" requests need to be as rigorously designed as any customer-facing journey. A single point of human discretion, exercised under the appearance of legitimate authority, was apparently enough to expose regulated personal data — a vulnerability that governance frameworks and staff training are meant to close.
The Renascence take
Breaches like this are rarely a technology story; they are a service-design and decision-architecture story. The failure point sits at the moment a frontline or back-office employee must decide, in real time, whether a request is genuine — and that decision was made easier to get wrong by the appearance of official credibility.
Most coverage of this incident will focus on cybersecurity hygiene, but the real lesson is behavioral: authority cues — an official-looking domain, formal language, urgency — reliably override caution, even at sophisticated, highly regulated institutions. A customer-obsessed operator should treat data-release requests the same way it treats high-value transactions: with mandatory friction, independent verification through a second channel, and a default posture of scepticism regardless of how credible the sender appears. Trust, once extended to a domain name instead of a verified process, becomes the vulnerability itself.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in Banking
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.