Curated coverage· general

Revolut hit by data breach after fake government email scam

A sophisticated phishing scam using official government emails compromised sensitive customer data at Revolut, highlighting new risks for digital finance.

Curated by Financing Your Way from original reporting by Finextra — Lending. Summary is AI-assisted and editorially reviewed — see our editorial standards.

FYWBy Financing Your Way EditorialSeptember 14, 2026

Revolut has confirmed a significant data breach involving sensitive customer information, including passport details. The breach occurred because hackers gained access to a legitimate government agency's email domain to send fraudulent data requests. Because the emails appeared to be from an official government source, Revolut's systems or staff complied with the requests, thinking they were fulfilling legal obligations. For retailers and operators who offer financing, this is a wake-up call regarding the security of your customer data. Even if you use a third-party lender like Revolut, a breach at the lender level can damage your customers' trust and potentially involve your business in legal or PR fallout. This incident proves that 'official-looking' emails are no longer enough to verify a request for data. Modern scams are now leveraging high-authority domains to bypass traditional security filters. If you collect customer information for financing applications, ensure your team knows that even 'government' emails must be verified through secondary channels. As digital banking and BNPL services become more integrated into retail, the surface area for these attacks grows. You should review your service-level agreements with financing partners to understand how they protect the data your customers provide during the checkout process.

Source: Finextra — Lending

Who else is covering this

Related coverage from across the industry

← Return to the library· Submit a correction