Business 24 sources · over 5 days Latest coverage 16 Sept 2026, 6:37 pm UTC

Revolut Data Breach: Customer Details Exposed by Fake Government Email Scam

Revolut has disclosed that scammers posing as government officials accessed sensitive customer data, including passports and financial records, by exploiting a compromised official email, with investigations ongoing in Italy and beyond.

By Grace Whitfield · First published 16 Sept 2026

In brief

  1. Revolut mistakenly shared sensitive customer data with scammers who used a compromised government email address.
  2. The breach affected more than 700 customers worldwide, with a significant focus on high-profile accounts.
  3. Personal information such as passports, selfies, and transaction histories was exposed during the incident.
  4. Italian authorities are investigating, as the attack reportedly used a real email account from the Italian police.
  5. Hackers are now demanding a ransom and claim to possess additional police data, raising concerns about further leaks.
Revolut Data Breach: Customer Details Exposed by Fake Government Email Scam
Source: The Next Web

Timeline · 6 moments

6 moments Open the full timeline →

Revolut confirms breach involving fake government requests

TechCrunch ↗

Revolut admits sensitive data, including passports, was exposed

Публикации по подписке ↗

Details emerge on compromised government email used in scam

The Next Web ↗

Italian police investigate breach and compromised PEC email

RSS di - ANSA.it ↗

Hackers claim to possess Italian police data and demand ransom

La Repubblica ↗

Reggio Calabria prosecutors open inquiry into Revolut case

Fanpage ↗

How it started

In early September 2026, the British fintech company Revolut fell victim to an elaborate scam. Criminals posing as government officials contacted Revolut, using what appeared to be a legitimate government email account. The attackers requested sensitive customer data, which Revolut staff believed to be an official inquiry and consequently provided access to the requested information.

Initial reports did not specify the country involved, but suspicions soon pointed towards Italy. Investigations suggested that the scammers used a real email address belonging to Italian law enforcement, which had likely been compromised prior to the attack.

How it unfolded

On September 12, 2026, Revolut publicly confirmed the data breach, revealing that customer information had been exposed after falling for fraudulent government requests. The company clarified that the breach was not due to a technical failure but rather to trust in a compromised official email.

As more details emerged, it became clear that the breach involved highly sensitive data, such as passports, selfies, and financial transaction histories. Reports indicated that the attackers specifically targeted high-value accounts, including those of prominent individuals. The number of affected customers was estimated at around 700, spread across more than 30 countries.

By September 15, Italian media reported that the compromised email belonged to the Reggio Calabria prefecture and was used to impersonate police investigators. Italian authorities, including the national anti-mafia and anti-terrorism units, launched official investigations into the incident, focusing on both the breach and the security of government email systems.

Shortly afterward, hackers began demanding a multimillion-dollar ransom from Revolut, threatening to release more stolen data if their demands were not met. They also claimed to have accessed large volumes of internal police data, which heightened concerns about wider system vulnerabilities.

Where it stands

Revolut has acknowledged the breach and is working with law enforcement agencies to investigate and contain the incident. The company maintains that customer funds remain secure and that only a small fraction of users were impacted.

Italian police and prosecutors continue to probe how the attackers gained access to an official government email account and whether other agencies might be at risk. Meanwhile, the hackers' ransom demands and claims of further sensitive data in their possession have put additional pressure on both Revolut and Italian authorities.

What to watch

Authorities are still investigating whether other government systems have been compromised and if more data could be leaked. The outcome of the ransom negotiations and the full scale of the breach remain uncertain, with potential implications for digital banking security and government IT infrastructure.

Written from 24 outlets' coverage of this story. Every timeline entry links to the original report.

More in Business

All →