Skip to content
logo The magazine for digital lifestyle and entertainment
Fraud News Online-Banking Security All topics
Is There Compensation?

Revolut Shared Sensitive Customer Data with Fraudsters

Several bank and payment cards are tucked into a black cardholder. In the foreground, a blue Revolut card with a white Revolut logo is visible. Behind it, more cards in various colors are protruding.
Cybercriminals are believed to have accessed sensitive customer data from Revolut Photo: Getty Images

September 14, 2026, 3:50 pm | Read time: 3 minutes

The British company Revolut has fallen victim to identity fraud. Attackers allegedly posed as employees of a legitimate authority and submitted information requests to the company. Revolut apparently considered the requests legitimate and reportedly released sensitive, personal customer data. Affected data includes ID documents, verification selfies, and transaction data.

What is known about the incident

According to Revolut, which officially confirmed the incident to media outlets, the company was not the victim of a classic cyberattack. Instead, an unauthorized third party sent an email using a government domain, posing as an authorized contact. The request appeared credible to the fintech company.

It was only later discovered that the email did not originate from an authorized person. Revolut describes the incident as a “sophisticated fraud through identity theft.”

What data is affected?

The nature of the potentially disclosed information is particularly critical. According to a report by the online magazine “TechCrunch,” the following data may be affected:

  • Identity and contact data, including birth dates
  • Postal and email addresses
  • Phone numbers
  • Copies of ID documents, including passports and driver’s licenses
  • Verification selfies
  • Bank statements
  • Transaction histories

As a Revolut user reported on X on September 11, IBANs, withdrawal receipts, and complete transaction histories, including Bitcoin transactions, were also disclosed. However, the company emphasizes that its own systems were not compromised at any time. Customer funds were also reportedly not affected by the incident.

X Corp. placeholder
Here you will find content from third-party providers
To interact with or display third-party content, we need your consent.

Many questions remain unanswered

Revolut mentions a “limited” number of affected customers. However, a specific number has not yet been disclosed. It is also unclear from which countries the affected individuals come. The bank claims to have over 80 million customers in more than 30 countries.

As Revolut explained to TechCrunch, the company responded immediately after discovering the incident. The email was blocked immediately after the incident was discovered, and the affected authority was informed. Law enforcement agencies, as well as data protection and financial supervisory authorities, have also been involved.

More on the topic

What rights do those affected have

Even though no passwords or customer funds are believed to have been leaked, the potentially disclosed information is extremely sensitive. With copies of IDs, personal data, and account information, targeted fraud attempts can be prepared. Affected individuals should therefore be particularly vigilant for unusual emails, SMS, or calls in the coming weeks.

Also of interest: Klarna to link credit card to paid subscription in the future

For customers, the General Data Protection Regulation (GDPR) provides several rights. According to “Netz Trends,” under Article 15 of the GDPR, individuals can request information about which personal data is affected and to whom it may have been disclosed. Such a request can be directed to Revolut Bank UAB. Additionally, under Article 77 of the GDPR, there is the option to file a complaint with the data protection authority at one’s place of residence, which would then be forwarded to the authority responsible for Revolut in Lithuania.

Possible compensation

Furthermore, there may be potential claims for compensation. Article 82 of the GDPR provides for compensation for material and non-material damages. Whether such a claim actually exists depends on the individual case.

It also remains open whether Revolut has complied with all legal reporting obligations. Under Article 33 of the GDPR, data breaches must generally be reported to the relevant supervisory authority within 72 hours.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.