Tuesday, 15 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 15 September 2026 at 08:56

Revolut confirms data breach after fraudsters spoofed a government agency's email

Fintech firm Revolut has confirmed that fraudsters, abusing a legitimate government agency's email domain, tricked it into handing over customer personal data and ID documents; a hacker group now threatens to leak the data unless paid.

Foto: Malwarebytes

What happened

London-based fintech Revolut has admitted disclosing sensitive customer records to an unauthorized party after accepting fraudulent information requests sent from a genuine government agency email domain, according to TechCrunch and Malwarebytes. Revolut describes the incident as an external impersonation scam rather than an intrusion into its own systems, and says customer funds, accounts, and core infrastructure were not affected.

What data was exposed

The disclosed information includes customers' identity and contact details — date of birth, postal and email address, and phone number — as well as copies of identity documents such as passports and driver's licenses, facial verification selfies, account statements, and transaction histories, according to a notification email sent to affected customers and reviewed by TechCrunch. Revolut says only a "limited" or "very limited" number of customers were affected but has not disclosed an exact figure. Crypto security researcher ZachXBT said the attack appeared to target high-net-worth users.

Extortion threat

City AM reports an element not mentioned by the other sources: a hacker group calling itself "Revolut Smilik" told the outlet it is demanding payment from Revolut and threatened to release "more and more data everyday" if the ransom is not paid. According to City AM, data on several notable individuals has already been leaked, though the company and the hackers have not yet had direct contact.

Response and oversight

Revolut says it blocked the fraudulent email address immediately upon detection and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators, but it has not named the agency or the country involved. The UK's Financial Conduct Authority (FCA) and the Information Commissioner's Office (ICO) both confirmed they are aware of the incident and are assessing it.

Context

Revolut operates in more than 30 countries and serves over 80 million customers globally. The incident comes as the company, according to TechCrunch, is reportedly weighing a public listing that could value it at up to $200 billion, up from a $75 billion private valuation in November; City AM, however, notes that a secondary share sale launched earlier this year values the firm at around $115 billion. Malwarebytes advises affected customers to treat unexpected Revolut-related calls or messages with suspicion and to monitor their accounts and credit history.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category