Skip to main content
RevolutSecurity incident

Revolut confirms customer data breach through fake government requests

What happened

Revolut confirmed it suffered a data breach, exposing sensitive customer information to an unauthorized third party who used fraudulent requests from a legitimate government agency email domain.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers' identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver's licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification. A Revolut spokesperson confirmed to TechCrunch that a "limited" number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved. "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the spokesperson said. Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party and alerted the...

Keep reading with a free account

The rest of this article, and every signal for Revolut, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Location
London, England, United Kingdom

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information

Extraction

Confidence
95%
Detected
Sep 12, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Revolut and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Revolut this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/8242f4c2-f40f-c8be-09f6-e815b9afeeff returns this record as JSON. POST /v1/companies/enrich returns every signal for revolut.com.

{
  "signal_id": "8242f4c2-f40f-c8be-09f6-e815b9afeeff",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-12T14:40:00+00:00",
  "company": {
    "name": "Revolut",
    "domain": "revolut.com"
  },
  "data": {
    "url": "https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/",
    "title": "Revolut confirms customer data breach through fake government requests",
    "author": "Jagmeet Singh",
    "excerpt": "British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification. A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved. “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said. Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party and alerted the...",
    "summary": "Revolut confirmed it suffered a data breach, exposing sensitive customer information to an unauthorized third party who used fraudulent requests from a legitimate government agency email domain.",
    "location": "London, United Kingdom",
    "planning": false,
    "image_url": "https://techcrunch.com/wp-content/uploads/2025/11/revolut.png?resize=1200,629",
    "confidence": 0.95,
    "published_at": "2026-09-12T14:40:00Z",
    "location_data": [
      {
        "city": "London",
        "state": "England",
        "region": "Northern Europe",
        "country": "United Kingdom",
        "continent": "Europe",
        "fuzzy_match": false
      }
    ],
    "vulnerability": "sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information",
    "article_sentence": "British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.