BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Revolut Phishing Attack Exposes Sensitive Customer Data

Revolut customers had sensitive identity and financial records exposed after fraudsters posed as a government body and tricked the fintech into handing over data, according to a single incide

AnonymousCryptoCompass newsroom
September 12, 2026
4 min read
NEWS
Revolut Phishing Attack Exposes Sensitive Customer Data
CryptoCompass editorial visual for policy coverage.

Revolut customers had sensitive identity and financial records exposed after fraudsters posed as a government body and tricked the fintech into handing over data, according to a single incident report. The Revolut phishing attack reportedly swept in identity documents, verification selfies, IBANs and even Bitcoin-related transaction activity.

The details come from Crypto Briefing, which reports that an impersonated government data request caused the disclosure of customer identity and financial records. The outlet says Revolut characterized the event as an external impersonation scam, not a breach of its internal systems. For related coverage, see Revolut EURR Stablecoin Launch: What to Know.

No original customer notification, regulatory notice or forensic report has been independently obtained. Every incident detail here traces back to that one report, so treat it as attributed reporting rather than confirmed fact. For related coverage, see Roundhill, Teucrium Shift XRP ETF Dates to October 11.

What is known about the Revolut phishing attack

According to unconfirmed reports, the attackers sent a fraudulent request dressed up as a legitimate government demand for data. Revolut then disclosed the information before the request was flagged as fake. For related coverage, see Hey Wallet Sunsets Products, Impacting Solana Users.

The report dates the start of customer notifications to September 11, 2026. The breach date itself, the impersonated agency and the original email headers were not disclosed, so it is not clear when the actual disclosure happened. For related coverage, see CFTC Probes Polymarket Trades: Biden Pardons, Iran, Google.

This is not Revolut’s first reported brush with a fake-government-request scenario. Earlier coverage described a similar Revolut data leak involving passports and Bitcoin records, and the overlap between the two accounts has not been fully resolved.

What the exposure means for Revolut customers

Crypto Briefing lists the exposed data as identity documents, verification selfies, names, dates of birth, contact information, IBANs, withdrawal histories and Bitcoin-related transaction activity. That is a rich haul for anyone building a targeted fraud campaign.

The exact number of affected customers has not been established. The report describes the group as limited without giving a count, and says systems and customer funds were unaffected, though those are reported assurances, not independently audited findings.

Exposure is not the same as account compromise. According to unconfirmed reports, no passwords, PINs, private keys or customer funds were taken. Data leaks like this typically fuel follow-on phishing rather than direct theft, but that is a potential risk here, not a documented outcome of this incident.

The Bitcoin angle is why the crypto world is watching. Bitcoin traded at $77,152 at retrieval time, but there is no established link between that price and this incident.

Precautions Revolut customers can take

The clearest defense is Revolut’s own general fraud advice. The company’s guidance identifies impersonation of tax officials, police or Revolut itself as a known scam pattern, and tells people to contact the supposed organization through its official contact details instead of sharing information under pressure.

As general practice, open the Revolut app directly to check any message rather than following links in unsolicited emails or texts. Never share passwords or one-time security codes with anyone who contacts you first.

Review recent account activity and report anything unfamiliar through official support channels. This is standard precaution, not remediation advice attributed to Revolut, which has not published incident-specific instructions that could be verified here.

One technical footnote matters. Even if a fraudulent email passes domain authentication checks like SPF, DKIM and DMARC, that proves nothing about legitimacy; the DMARC specification explicitly states that authenticated email should not receive elevated delivery privilege. A message that looks technically valid can still be a scam.

So the real question hangs over the notification list: how many customers are about to find their passports and payment histories in the wrong hands, and who exactly waved the fake request through?

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

The article Revolut Phishing Attack Exposes Sensitive Customer Data first featured on theccpress.com.