
Revolut admitted it handed sensitive customer files to criminals who impersonated a government agency using a real official email domain, raising fresh doubts about how institutions protect the most personal data we are forced to share.
Story Highlights
- Revolut says scammers used a real government email domain to request customer records.
- The company says its systems and customer funds were not touched, but data was exposed.
- Regulators and reports point to a social engineering scheme, not a direct hack.
- The episode shows how easy it can be to turn trust in government channels against the public.
What Revolut Says Happened
Revolut said criminals sent data requests from an email account operating inside a legitimate government domain. Staff treated those messages as official and released files for a limited group of customers. The company stated that its own systems were not breached and that no customer funds were taken. Reuters reported the disclosure and quoted Revolut’s statement that the incident’s scope was limited and funds were unaffected.
Security write-ups and customer notices describe the exposed data as highly personal. These records can include identity details and copies of documents used to verify accounts. They can also include account and transaction history. Tech coverage of the company’s notice to affected users lists these categories, underscoring why victims face a real risk of targeted scams after the leak, even if their money in accounts was not directly touched.
Why This Method Works on Big Institutions
Investigators and regulators frequently warn that social engineering beats firewalls by exploiting trust. Criminals borrow the look and feel of authority to trigger fast compliance. The European Union’s cybersecurity reporting on the finance sector ranks social engineering among the top breach patterns, alongside system intrusion and web app attacks. External actors drive most breaches, usually seeking money or data that leads to money. Revolut’s case tracks that pattern: no code-level hack, but real data loss.
This distinction matters for customers. A company can honestly say “our systems were not breached” while victims still suffer identity theft, account takeover attempts, or blackmail. The public often hears “no systems breach” as “no big deal.” That gap can hide real harm. Prior fintech incidents show the same split: attackers trick a person or process, not a server, yet the fallout for users is the same—exposed identity data and new waves of targeted fraud attempts.
How Many People Were Affected—and What We Know
Reports differ on the count. Some coverage cites hundreds of notified users. Others cite regulator summaries pointing to broader exposure. Lithuania’s data authority, where Revolut holds a banking license, said the breach was caused by social engineering and listed typical personal data fields that were accessed. Revolut says it blocked the sender once it detected the scheme and notified the government body, police, and privacy regulators, as required after such events.
!! BREAKING NEWS !! Revolut hackers demanded 6,000 Monero (≈$3M) following a customer data breach, setting a 24-hour ransom deadline. #Cybersecurity #DataBreach #Crypto
— PiEDawg (@PiEDawg_) September 16, 2026
Claims have surfaced online about mass datasets for sale. Revolut has pushed back on unverified listings that lack samples or technical detail, a common move when platforms try to sort real extortion from internet noise. Still, even smaller confirmed leaks can feed years of identity fraud. Once copies of passports or selfies circulate, you cannot “change” that data like a password. That is why these incidents feel like a rigged game to many customers.
What This Signals About Governance and Trust
This breach strikes at a core promise: that the records we share by law will be guarded with care. Revolut says the email came from inside an official government domain, which means trust in government channels became the weapon against citizens. People across the political spectrum worry that large institutions protect themselves first and clean up later. Events like this deepen that view and widen the sense that accountability only arrives after damage is done.
Lawmakers on both sides often talk tough after breaches, but progress is slow. Clear checks for any “urgent” data request, out-of-band callbacks to named officials, and signed warrants verified through a separate registry are all basic steps. The Federal Trade Commission advises firms to document, contain, and investigate quickly after a breach, and to improve the process to prevent a repeat. Customers deserve proof these controls are in place before the next email arrives.
What Customers Can Do Right Now
Affected users should assume criminals will use the leaked details to sound legitimate. Watch for tailored phishing by email, text, and phone. Freeze credit files where available. Use strong passwords and unique codes for each service. Turn on multi-factor authentication. Do not trust any “official” outreach that urges fast action—call back using a published number, not one in the message. If your identity document was exposed, ask your issuer about added protections and replacement steps.
Sources:
insiderpaper.com, nltimes.nl, bankinfosecurity.com, x.com, infostealers.com, cypro.co.uk, amlintelligence.com, pasqualepillitteri.it


















