Revolut Covered Costs Following September Data Breach

The fintech firm funded document replacements after unauthorized access affected 680 customer accounts.

Updated on Oct. 7, 2026 in Cybersecurity

Revolut Covered Costs Following September Data Breach

Live Poll

Do you trust digital banking platforms to keep your identity documents secure from hackers?

On September 12, 2026, Revolut announced it would pay for the replacement of identification documents for 680 clients following a security breach. The incident involved an unauthorized third party using a government email domain to access personal data.

Why it matters

The breach exposed sensitive personal data, including passports and account histories, after attackers bypassed verification protocols through a fraudulent email scheme. By covering replacement costs, the company aims to mitigate the long-term identity theft risks faced by those impacted.

The incident impacted 680 accounts and exposed documents such as passports, driver licenses, and transaction histories. Revolut subsequently blocked the compromised government email domain used to facilitate the fraudulent information requests.

The players

Revolut

This global financial technology company offers banking services and currency exchange through a digital platform.

The details

The breach occurred when an unauthorized party used a spoofed government email domain to submit illegitimate data requests, gaining access to birth dates, phone numbers, and home addresses. Following detection, the company alerted financial regulators and law enforcement while managing extortion threats from a hacker.

Timeline

  1. September 12, 2026: Revolut notified customers and the media regarding the data breach.

  2. September 16, 2026: Reports emerged detailing extortion threats made by a hacker against the firm.

The Tech Race

This incident follows a pattern set by the 2022 Revolut data breach where security vulnerabilities led to unauthorized third-party access. It underscores the ongoing industry struggle to verify identity requests that leverage trusted government communication channels.

Affected customers were provided financial support for the replacement of compromised government identification documents. Users of digital banking platforms should remain vigilant for phishing attempts that utilize spoofed official email domains to request account information.

The takeaway

This incident highlights how attackers increasingly weaponize trusted government domains to bypass security verification processes. Consumers should monitor their financial statements closely and utilize credit monitoring services after any provider reports a compromise of identity documentation.

Further reading

Learn more about evolving digital threats in the Cybersecurity section.

Live Poll

Do you trust digital banking platforms to keep your identity documents secure from hackers?