← All articles
BREAKING

Revolut data breach explained

What happened, and what it means for your business

Revolut has confirmed that customer data was handed over to scammers after staff were targeted by a phishing email impersonating a government agency.

This wasn't a break-in. Revolut's own systems weren't compromised, and the company says customer funds are unaffected. Someone simply asked for the data and was convincing enough that someone at Revolut believed them.

What happened

An unauthorised party sent Revolut a request using an email address on a genuine government agency's domain, according to reporting from TechCrunch and Help Net Security.

Revolut treated the request as legitimate and disclosed customer information in response. The company has since discovered the scam, blocked the email address, and notified the relevant authorities, regulators, and affected customers directly.

Attackers have since begun publishing some of the stolen data and are demanding payment, threatening further daily releases until Revolut pays.

The story is still developing, and we may not understand the full impact of the breach for some time.

What was exposed

Reported categories of exposed data include full names, dates of birth, postal and email addresses, phone numbers, passport and driving licence copies, verification selfies, account statements, and transaction histories.

Revolut has said biometric facial telemetry data was not involved. Coverage also indicates the attack was concentrated on high-net-worth customers rather than the customer base broadly.

Why this matters beyond Revolut

It's tempting to read this as a story about one bank's mistake. It's really a story about how modern phishing works.

Nobody had to break through a firewall or exploit a piece of software. The attacker needed one email, sent to one person, made to look like it came from somewhere it didn't. That's the entire attack.

Sophos's 2026 State of Ransomware report found that malicious email and phishing together account for roughly half of all ransomware attacks -- making them, combined, the single biggest way attackers get in.

Any business that handles sensitive customer or financial data -- and shares it with staff who make judgement calls about incoming requests -- has the same exposure Revolut did.

How Phishing Simulations would have helped

The email that got through to Revolut's staff was convincing enough to look official. That's exactly the scenario our Phishing Simulations are built to test for.

A simulation puts a realistic, well-disguised request in front of your own team, safely, so you find out how they'd respond before an attacker does. Would they verify the request through a second channel? Would they escalate it? Or would they do what Revolut's staff did, and simply comply?

Paired with Security Awareness Training, simulations turn "we have a policy for this" into "our team actually follows it under pressure".

Getting started

Phishing Simulations and Security Awareness Training are optional add-ons available to HackRisk subscribers.

In the meantime, you can claim your HackRisk Report any time you like. It's completely free and arrives within 24 hours.

For more information about Phishing Simulations and Security Awareness Training in more detail, get in touch today.

Sources

*Revolut confirms customer data breach through fake government requests, TechCrunch, 12 September 2026*

*What we know about the Revolut data breach so far, Help Net Security, 14 September 2026*

*Revolut Data Breach Exposes Customers' Passport Copies and Full Transaction Histories to Hackers, Cyber Security News*

*Revolut Data Breach: Hackers Demand Ransom, Threaten Daily Customer Data Dumps, Parameter*