Revolut suffers phishing attack, sensitive customer data compromised
Fraudsters pose as government agencies to trick fintech company Revolut into handing over data, exposing sensitive identities and financial records of its customers, according to an incident report. The phishing attack against Revolut reportedly involved identity documents, verified selfie photos, IBAN (International Bank Account Number) and even bitcoin-related transaction activity.
These details stem from Crypto Briefing reports that a forged government data request led to the disclosure of customer identities and financial records. According to the report, Revolut characterized the incident as an external fraud rather than an intrusion into its internal systems. No original customer notices, regulatory announcements or forensic investigation reports have been independently obtained. All incident details described here are traced back to the single report mentioned above and should therefore be regarded as well-defined reports rather than confirmed facts.
What is known about the Revolut phishing attack
Based on unconfirmed reports, the attacker sent a fraudulent request disguised as a legitimate government data request. Before the request was marked false, Revolut had disclosed relevant information. The report stated that customer notices began on September 11, 2026. However, the specific date of the leak, the name of the fake institution and the original email header information have not been disclosed, so the actual time when the leak occurred is not clear.
This is not the first time Revolut has encountered such a forged government request. Previous reports have described a similar Revolut data breach involving passports and Bitcoin records, but the connection between the two incidents has not yet been fully clarified.
Impact of the data breach on Revolut customers
The leaked data listed by Crypto Briefing include: ID, verification selfie photos, name, date of birth, contact information, IBAN, withdrawal history and bitcoin-related transaction activities. This is a valuable "trophy" for individuals aiming to implement targeted scams.
The exact number of affected customers has not yet been determined. The report only stated that the number of affected groups was limited, but did not provide specific numbers and said systems and client funds had not been affected. It should be noted that these are assurance statements in the report and not the results of an independent audit.
Data breach is not the same as account theft. According to unconfirmed reports, no passwords, PIN codes, private keys or customer funds were stolen. Such data breaches typically encourage subsequent phishing attacks rather than outright theft, but in this case they are only a potential risk rather than a documented result.
Developments in Bitcoin have attracted the attention of the cryptocurrency industry. At the time of retrieval, the price of Bitcoin was US$77,152, but there is currently no evidence that this price is related to this event.
Precautions that Revolut customers can take
The clearest defense is to follow Revolut's own general anti-fraud recommendations. The company's guidelines point out that impersonating a tax official, police officer or Revolut is itself a known pattern of fraud and advise people to contact them through so-called official contact methods of the organization, rather than sharing information under pressure.
As a general practice, please open directly in the Revolut app to verify any messages, rather than clicking on links in unsolicited emails or text messages. Never share passwords or One-Time Security Captcha with anyone who proactively contacts you.
Review recent account activity and report any unfamiliar situations through official support channels. This is a standard precaution and not a remediation recommendation attributed to Revolut as Revolut has not issued an event specific directive that can be verified in this report.
There is a technical note worth noting. Even if fraudulent emails pass domain authentication checks such as SPF, DKIM, and DMARC, this does not prove legitimacy; the DMARC specification clearly states that authenticated emails should not receive higher delivery privileges. Information that seems technically valid can still be a scam.
So the real open question is: How many customers on the notification list are about to discover that their passports and payment histories are in the hands of others? Who allowed this forged request to pass the review successfully?
Disclaimer : This article is for information reference only and does not constitute financial or investment advice. There are significant risks in the cryptocurrency and digital asset markets. Be sure to conduct independent research before making a decision.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC