Revolut Data Leak Exposes Security Gaps Beyond Fines
Revolut’s mobile-first model has helped it reach more than 80 million customers and operate as a bank in over 30 countries, concentrating identity, account and transaction data in a fast-growing platform. The risk is not new: a September 2022 social-engineering attack exposed data tied to 50,150 customers worldwide, including 20,687 in the European Economic Area. The repeated failures sharpen concern that regulatory penalties alone cannot correct weaknesses in verification, access controls and security governance.
On Sept. 11-12, 2026, Revolut notified affected customers that it had fulfilled fraudulent information requests sent from an unauthorized mailbox inside an official government domain. The messages carried valid domain-authentication credentials; records disclosed may have included passports, verification selfies, IBANs, withdrawal data and full transaction histories, including Bitcoin activity. Revolut said its systems and customer funds were unaffected, but did not disclose the number of people involved. The Bank of Lithuania’s separate €3.5 million anti-money-laundering fine on April 8, 2025, underscores how sanctions have yet to dispel broader control concerns.
All Coverage
1 original reportsThe Backstory
The history behind this eventRevolut Rejects Claim of 75 Million-Customer Data Breach
Revolut, a UK-based fintech company offering banking and payment services through its mobile app, has a large customer base that makes any alleged data exposure a significant cybersecurity concern. Listings of financial records on dark-web forums can raise the risk of fraud and identity theft, while also testing customer confidence and drawing scrutiny of a company’s data-protection controls.
As of Aug. 3, 2026, a hacker claimed to be selling 75 million purported Revolut customer records on the dark web for $500. Revolut said it compared and validated the material and found no evidence that its systems had suffered a data breach. The company concluded that the dataset was highly likely to have been fabricated rather than obtained from genuine customer records.
Revolut, Fed Incidents Expose Cracks in Banking’s Trust System
Banks typically treat authenticated government requests and regulatory data systems as trusted infrastructure, but incidents involving digital lender Revolut and the U.S. Federal Reserve show why that assumption is increasingly risky. A valid email domain can conceal an unauthorized operator, while an outage at a supervisor’s data hub can disrupt oversight without touching a bank’s core systems. The cases broaden operational-resilience planning beyond internal networks to government channels, regulators and independent verification of a requester’s legal authority.
Revolut said on Sept. 12, 2026, that an unauthorized party used a legitimate government-agency email domain to submit fraudulent information requests, exposing data that may have included identity documents, verification selfies, IBANs and transaction histories. The company said only a limited number of customers were affected and that its systems and customer funds were untouched; it disclosed neither a victim count nor a loss amount. Separately, Senator Elizabeth Warren said on Sept. 15 that the Fed’s National Information Center had been down for at least 48 hours from around Aug. 5, and asked whether a 30% staffing cut impaired maintenance.
Hackers Demand $3 Million Ransom From Revolut
British fintech Revolut disclosed customer information after fraudulent data requests were sent from an email account on a legitimate Italian government domain. The incident did not involve a direct intrusion into Revolut’s core systems, but exposed identity documents, contact details, IBANs, account statements and transaction histories. The case is significant because it shows how attackers can exploit trusted channels to bypass institutional controls, a growing risk for fast-expanding digital banks holding both financial and know-your-customer records.
On Sept. 16, 2026, the group iamnotavillain demanded $3 million in Monero and gave Revolut 24 hours to pay, threatening to sell confidential records to other criminal groups. Reports said about 680 customers were affected, with some apparently selected for substantial cryptocurrency holdings. Revolut said customer funds and internal systems remained unaffected. The company said it had blocked the email source, contacted affected clients and notified law-enforcement, data-protection and financial regulators.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →