Revolut confirmed on September 12, 2026 that it disclosed sensitive records after fraudulent requests arrived from a legitimate government agency email domain. The incident was a failure to authenticate and verify a purported legal data request—not a reported intrusion into Revolut’s core banking infrastructure.
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened in the Revolut data breach confirmed on September 12, 2026—including how attackers impersonated a legitimate government agency. Article summary: Revolut confirmed on 12 September that it had disclosed sensitive customer records to an unauthorised party after responding to fraudulent requests sent from a genuine government-agency email domain. This was a social-en. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts w
Revolut says an unauthorised party obtained sensitive customer information after the company responded to fraudulent requests sent from a legitimate government-agency email domain. The September 12 disclosure is significant because the attackers apparently did not need to break into Revolut’s core systems: they exploited trust in an official-looking communication channel. Revolut says affected customers were contacted and that customer funds and its systems were unaffected. 1
34
Revolut confirmed that fraudulent information requests came from an email address on a legitimate government-agency domain and resulted in customer information being disclosed to an unauthorised third party. The company described the incident as a “sophisticated external impersonation scam,” said it blocked the address after detection, and said it alerted relevant authorities. 1
34
48
This distinction matters. The available reporting does not establish that attackers breached Revolut’s core banking infrastructure or accessed customer funds. It does establish that a process for handling sensitive external requests was deceived. 1
34
The confirmed element is narrow but consequential: the requests used a real government-domain email address. A technically authentic-looking sender domain can make a fraudulent request appear routine, particularly where teams handle legal or law-enforcement requests at speed. 1
35
Some subsequent reporting linked the sender to Italy’s PEC certified-email infrastructure and to the Interior Ministry’s pec.interno.it domain. That attribution has not been independently confirmed by Revolut or Italian authorities in the material available here, so it should be treated as a reported lead—not an established account of the attack. 37
The broader lesson is that email-domain authenticity alone is not adequate proof that a demand for highly sensitive data is legitimate. A request should be verified independently through a known agency contact route and subjected to escalation controls before records are released.
Revolut initially said the breach affected a “very limited” number of customers and did not publish a figure. 1
Later reporting put the total at roughly 680 customers worldwide, with 12 Irish customers reported among them. Revolut had not publicly confirmed that count in its initial statement, so the figure should be understood as reported rather than as a number directly announced by the company. 33
Reports also relayed an attacker claim that the operation involved access to Italian law-enforcement systems over approximately six months. That is an unverified claim by the alleged threat actor, not a confirmed finding by Revolut or authorities. 36
37
Customer notifications reviewed by TechCrunch said the disclosed material included identity and contact information such as dates of birth, postal and email addresses, phone numbers, and copies of passports or driving licences. The notification said the information may also have included verification selfies, account statements and transaction histories. 35
Other reporting described IBANs, withdrawal records and Bitcoin transaction activity among the material allegedly obtained. 5
10
Taken together, this is a particularly sensitive combination: identity documents can support impersonation and account-recovery fraud, while contact and financial information can make phishing attempts appear unusually credible.
A name, address, identity document and verification selfie can link a real person to financial activity. Where Bitcoin transaction history is included, the exposure may make it easier to connect verified offline identity data with activity that is visible on a public blockchain. 10
35
That does not mean every wallet or future transaction is automatically attributable. But the combination can increase the likelihood of tailored phishing, identity fraud, coercion attempts and scams aimed at people perceived to hold crypto assets. Unlike a password, identity documents and past blockchain records cannot simply be changed after a leak.
Attackers were reported to have begun publishing customer material and threatening further releases. Reporting identified files said to belong to tennis player Alexander Shevchenko and Gamdom chief executive Felix Römer; Cointelegraph reported that Römer commented after his details appeared in the leak. 2
A purported demand for 10,000 BTC—reported as roughly $780 million at the time—circulated in posts and secondary reporting. Revolut did not confirm the demand, and neither did law enforcement in the cited material. It should therefore be treated as an unverified extortion claim, rather than a confirmed ransom negotiation. 12
13
Customers who received a notification should preserve it and follow Revolut’s official guidance. They should also be especially cautious about messages that cite personal details, claim to be from Revolut or a regulator, or create urgency around account security.
Useful defensive steps include:
In the UK, the Information Commissioner’s Office advises people concerned that an organisation has not kept their data safe to contact the organisation first and provides public support channels for data-protection concerns. 23
This incident shows why sensitive government or law-enforcement requests need controls beyond sender-domain checks. Effective safeguards can include independent callback verification using trusted directory details, dual approval for unusually sensitive disclosures, strict data minimisation, auditable request records and clear procedures for spotting authority-based social engineering.
For customers, the key takeaway is equally direct: an official-looking email address is evidence to investigate, not proof to trust. In a breach involving identity records and financial history, follow-on fraud can be more damaging than the initial disclosure itself.
The evidence supports that Revolut disclosed customer data after fraudulent requests from a legitimate government domain and that its core systems and customer funds were not affected, according to the company. 1
Important details remain unresolved in the supplied reporting: the precise role of PEC infrastructure, the alleged six-month timeline, the full number of customers affected, the attackers’ claimed access to Italian systems, and the status of any enforcement action by UK regulators. Those claims should not be presented as settled facts without official confirmation. 13
36
37
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Revolut confirmed on September 12, 2026 that it disclosed sensitive records after fraudulent requests arrived from a legitimate government agency email domain.
Revolut confirmed on September 12, 2026 that it disclosed sensitive records after fraudulent requests arrived from a legitimate government agency email domain. The incident was a failure to authenticate and verify a purported legal data request—not a reported intrusion into Revolut’s core banking infrastructure.
Claims involving Italy’s PEC certified mail system, a six month operation, an extortion demand and daily leaks remain unverified or only partly corroborated by reporting.