Fake Government Request Led to Revolut Customer Data Being Handed Over

According to customer notifications, Revolut complied with a fake request posing as a government demand. Potentially disclosed data includes identity documents, IBAN details and transaction history, including Bitcoin activity.

A fake government request posing as a legitimate demand led to sensitive data belonging to some Revolut customers being handed over. This is based on notifications the financial app sent to affected users and that foreign media cited. Revolut subsequently labeled the request fraudulent, blocked its source, and informed customers and regulators.

According to available information, the company has not confirmed a breach of its own systems or any loss of customer funds. The notifications reportedly stated that customers’ funds remained safe. Revolut has not disclosed the exact time when the data was handed over; information about the incident appeared on September 11 and 12, 2026.

Fake government request and the scope of possible data

Data that may have been provided based on the fake request includes identity documents, selfies used for identity verification, contact and address details, IBAN, statements, and transaction history. This also includes Bitcoin activity.

It is not publicly known how many customers were affected, which government agency was impersonated in the fraud, or which specific data categories concerned individual people. Key details so far come from customer notifications cited by the media; a publicly available primary statement from Revolut or a regulator’s decision could not be independently verified.

On-chain investigator ZachXBT said the fraud may have targeted high-net-worth customers. However, this claim has not been independently confirmed.

This is not a confirmed account breach

The case does not represent a confirmed technical hack of Revolut accounts or confirmed theft of cryptocurrency. According to Revolut, as cited by the media, it involved an external impersonation campaign and its systems were not affected.

However, the scope of the potentially disclosed data may mean an increased risk of targeted communication from scammers for affected customers. A combination of an identity document, address, banking details, and transaction information could be used for phishing or social engineering.

  • Customers should be more cautious with emails, phone calls, and messages requesting additional personal data, access codes, or transaction confirmations.
  • Any contact allegedly made on behalf of Revolut or a government agency should be verified through official contact channels, not through links or numbers included in an unexpected message.
  • Based on available information, the incident itself does not confirm that login credentials or funds in the accounts were compromised.

Questions surrounding request verification

The case highlights the risks involved in processing legal and government requests for data. A valid sender domain alone may not confirm that a request is legitimate or that the person communicating on behalf of an institution is genuine.

Further developments will show whether Revolut discloses the number of people affected, the more precise scope of the data provided, and changes to its process for verifying urgent requests. Any statement from the relevant authority or regulator is also being monitored, as are reports of any investigation or misuse of the data.

Sources

  • CoinDesk – Cites customer notifications about the fraudulent request, lists data categories, notes the absence of any reported loss of funds, and says the number of affected people is unknown.
  • The Crypto Times – Reports matching wording from a customer notification about misuse of an email address in a government agency’s domain, blocking the address, and notifying regulators.
  • Coinstrooper / BeInCrypto – Publishes a statement attributed to Revolut about an external impersonation campaign, unaffected systems, and customer funds.

Verified and updated: 09/12/2026 15:24

Sharing