Digital Bank Revolut Accidentally Sends Customer Data to Cybercriminals

Digital Bank Revolut Accidentally Sends Customer Data to Cybercriminals

2026-09-15 data

Amsterdam, Tuesday, 15 September 2026.
Revolut inadvertently sent sensitive data of 680 customers to cybercriminals after falling for a fraudulent request sent from a legitimate government email domain.

The Mechanics of Digital Banking and Compliance Innovation

To understand how this breach occurred, it is essential to examine the digital banking innovations that have propelled Revolut to success. Based in the United Kingdom, the British fintech pioneer has amassed a customer base exceeding 80 million globally [5]. Traditional banking relies on physical branches and manual paperwork, but Revolut’s core innovation lies in its fully automated compliance and digital identity verification pipelines [GPT]. This system allows users to open accounts within minutes by uploading verification photos, selfies, and government-issued identity documents directly through a mobile application [3][5][GPT]. This digital-first approach lowers operational overhead, speeds up onboarding, and provides seamless cross-border financial services [GPT].

How the Sophisticated Social Engineering Attack Unfolded

However, the very digital pipelines designed to streamline compliance were exploited in a highly targeted social engineering attack. On Saturday, 5 September 2026, an unauthorized third party initiated the breach by targeting Revolut’s customer support and compliance workflows [7]. The attackers did not hack into Revolut’s core databases; instead, they submitted fraudulent information requests using a legitimate email domain belonging to an undisclosed government agency [1][7]. Crucially, the communication was secured with valid domain authentication credentials, making the requests appear entirely authentic to Revolut’s automated systems and support staff [7]. Believing they were complying with a lawful government inquiry, Revolut inadvertently packaged and transmitted the requested customer dossiers [1][7].

Quantifying the Impact on Global and Dutch Customers

By Friday, 11 September 2026, and Saturday, 12 September 2026, the online bank confirmed that sensitive customer data had likely been shared with cybercriminals [7]. A subsequent investigation by BNR Nieuwsradio revealed that the breach compromised the records of approximately 680 customers worldwide, including 36 individuals in the Netherlands [6]. This means Dutch customers represented 5.294% of the total affected victims. The compromised data is highly sensitive, comprising birth dates, home addresses, phone numbers, email addresses, passport and driver’s license copies, verification selfies, transaction histories, withdrawal records, and bitcoin-related data [3][5][7]. Some of this leaked information has already been published on the dark web, including the passport of Dutch singer Yade Lauren and the identification documents of German crypto-casino owner Felix Römer [1][3].

Mitigation and Lessons for the Fintech Industry

Upon discovering the fraud, Revolut immediately blocked the compromised government email address and initiated emergency response protocols [1][5]. The fintech firm has proactively contacted all 680 affected individuals to provide ongoing support [6][7]. Revolut has also reported the incident to law enforcement, privacy watchdogs, and financial regulators [1][5]. Importantly, the bank has emphasized that its internal systems were not breached and that customer funds remain entirely safe [1][5]. For the broader fintech sector, this incident highlights a critical vulnerability: while automated identity verification and digital compliance pipelines offer immense operational benefits, they remain susceptible to highly sophisticated social engineering tactics that abuse legitimate communication channels [GPT].

Bronnen


Data breach Fintech security