FINTECH / SEPTEMBER 12, 2026

Revolut’s data disclosure: a familiar name is not proof.

The short answer

Revolut says fraudulent government-domain requests led to customer information being disclosed. The company says customer funds and its systems were unaffected. Customers should verify any follow-up independently.

Source and context ↗

What has been reported?

On September 12, The Block reported that Revolut received fraudulent information requests through a legitimate government agency’s email domain. Potentially disclosed records included identity documents, contact details, and financial histories. Revolut said it contacted affected customers; it did not identify the agency or give a customer count. These are attributed company statements, not findings from our own investigation. Read The Block’s reporting.

Why does this matter beyond Revolut?

The uncomfortable lesson: information about you can make an impersonator sound convincing. A caller who knows your address or a payment you made has information. That is different from having permission to direct your next payment.

Our analysis is that verification needs a separate channel. Imagine someone turning up with a photocopy of your bank statement. You would not hand them your keys just because the balance was right. Give a phone call the same treatment.

The rule to keep

Judge the requested action, not how much the caller knows about you.

What should customers do now?

  1. Start inside the app you already use. Check notices and contact support there, instead of using the contact details in an unexpected message.
  2. Pause any request to act urgently. Write down what the person wants: a code, document, payment, download, or approval. A confident introduction does not justify that action.
  3. Verify on your terms. The FTC recommends contacting a company using a website or number you already know is real, rather than a suspicious message’s link. FTC phishing guidance.
  4. Keep a record if something seems wrong. Save the message, timing, and what you did. If money has moved, use our scam recovery checklist.

Questions this story does—and does not—answer

Does this mean every Revolut customer is affected?

No such conclusion is supported by the reporting cited above. Use your own account’s notices and official support for your situation.

Is this proof that customers’ money was stolen?

No. A data disclosure and an unauthorized payment are different events. Do not turn one headline into evidence of the other.

What would change this explanation?

A fuller incident notice, an affected-customer count, or a regulator’s findings could change the picture. This page reflects the sources checked on September 12, 2026; it is not a live incident-status feed.

For another example of a trusted communication channel being misused, read our Trezor email incident explainer.

Sources and reporting notes

Source review: September 12, 2026. AI-assisted synthesis of linked reporting and public statements, with our own explanatory examples. We have not independently examined affected accounts, devices, or private incident records.

See our editorial policy. Send corrections to hello@richretards.com.