Revolut Data Breach Impacted 680 Accounts
The breach occurred after the firm responded to fraudulent requests sent from a government email domain.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust fintech companies to keep your sensitive personal and financial information secure?
A data breach at financial firm Revolut compromised the accounts of 680 customers across 33 countries. Hackers accessed verification photos, addresses, and account details after tricking the company into responding to fraudulent official emails.
Why it matters
The incident highlights the vulnerability of financial institutions to social engineering attacks using spoofed government communications. It underscores the risks that businesses face when sensitive verification processes are triggered by deceptive, seemingly legitimate requests.
The incident affected 680 accounts across 33 nations, with the highest concentration of impact in France and Switzerland. Although the breach compromised user verification photos and account data, core internal systems and customer funds remained unaffected.
The players
Revolut
Revolut is a global financial technology company that offers banking services, currency exchange, and cryptocurrency trading to millions of users.
The details
Unauthorized actors utilized a legitimate-looking government email domain to submit fake legal requests to Revolut, which the company fulfilled in error. Following the unauthorized data access, hackers released samples of the stolen information and sent blackmail threats to at least one crypto entrepreneur.
Timeline
July 2026: A local entrepreneur reported receiving blackmail threats involving the compromised information.
September 2026: The data breach incident officially emerged.
The Tech Race
This breach reflects an industry-wide struggle where institutions must balance high-speed legal compliance with the increasing sophistication of social engineering. It follows the pattern set by the 2020 Twitter account takeover, where external actors successfully bypassed security via human manipulation.
Customers should remain vigilant against phishing attempts or blackmail threats that leverage previously stolen personal information. Users may need to update verification photos or monitor their financial statements closely if they are contacted by unauthorized parties.
The takeaway
This incident serves as a reminder for users to verify the authenticity of all communication claiming to be from official government or corporate sources. Individuals should avoid engaging with parties that use private or sensitive data as leverage for extortion.
Further reading
For more information on the evolving threat landscape, visit the Cybersecurity section.
Live Poll
Do you trust fintech companies to keep your sensitive personal and financial information secure?







