Digital Transformation · 14 September 2026
Revolut Confirms Data Breach Via Fake Government Requests
Revolut has confirmed a customer data breach after attackers impersonated official government or law-enforcement channels to extract personal data, with the digital bank now notifying customers, regulators and law enforcement.
What happened
Revolut has confirmed a customer data breach after attackers used fraudulent government requests to extract personal information from the digital bank. The company has notified affected customers, relevant regulators and law enforcement agencies as it investigates how the fake requests were submitted and processed.
According to reporting from TechCrunch and Reuters, the incident centres on bad actors impersonating official government or law-enforcement channels to request customer data under the guise of legitimate legal process. Revolut has not disclosed the exact number of customers affected or the specific data fields exposed, but has acknowledged the breach and outlined the steps taken since discovery, including engagement with authorities.
Why it matters
For a digital-only bank whose entire value proposition rests on trust, speed and frictionless verification, this is a direct hit to the operating model rather than a peripheral IT issue. Data-request workflows exist precisely to balance regulatory cooperation against customer protection; if that channel can be spoofed, the exposure extends to every fintech and platform business that relies on similar third-party or government-request processes to move quickly.
The incident also lands at a moment when financial institutions are under growing pressure to authenticate not just customers, but the institutions and requests coming from outside their walls. It is a reminder that identity verification is now a two-way problem — proving who the customer is, and proving who is asking about the customer.
The Renascence take
Most coverage of this story will focus on the breach itself. The more interesting failure is procedural: a process built for legitimate oversight became the attack surface.
Financial institutions have spent years hardening customer-facing authentication while treating inbound "official" requests as inherently trustworthy — a legacy assumption that no longer holds. The fix isn't just tighter encryption; it's redesigning the verification of authority itself, with the same rigor and friction-testing normally reserved for customer onboarding. Any operator that hasn't stress-tested "who can ask us for data, and how do we know they're real" should treat this as their prompt to do so — quietly, before it becomes their headline.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in Digital Transformation
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.