FTFuture Technology
Revolut Had Customer Data Stolen via Fake Government Requests
SECURITY

Revolut Had Customer Data Stolen via Fake Government Requests

· 3 min read · By Nath Connell

Key takeaways

  • Revolut confirmed a customer data breach caused by attackers submitting fake emergency government data requests
  • Revolut has over 45 million customers across more than 35 countries as of mid-2026
  • The fake emergency data request attack vector has previously been used against Meta and Apple
  • The FBI has previously warned that cybercriminals actively purchase access to government email systems for this type of attack

Revolut has confirmed a customer data breach that should make anyone who uses online banking pay close attention, not because of some sophisticated zero-day exploit, but because of something much more unsettling: attackers faked government requests to extract customer data.

The company says it has notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators. But the details of how the breach happened are what matter here, and they point to a systemic vulnerability that goes well beyond Revolut.

How Emergency Data Requests Work, and How They Get Abused

Tech and financial companies operating in most jurisdictions are legally obligated to respond to emergency data requests from law enforcement agencies. These are expedited processes designed for urgent situations, things like imminent threats to life, active investigations into serious crime, or time-sensitive fraud cases. The idea is that waiting for a court order could cause harm, so companies have fast-track channels for verified government requests.

The problem is that verifying those requests is genuinely hard. Attackers who have access to compromised government email accounts, or who can convincingly spoof official communications, can submit fake emergency requests that look legitimate to the company receiving them. There is no universal, cryptographically secure authentication system for emergency legal requests. It is largely a human process, which means it has human failure points.

This is not a new attack vector. Meta confirmed in 2022 that it had been tricked by fake emergency data requests, and Apple reported similar incidents. The FBI has previously warned that cybercriminals were actively purchasing access to government email systems specifically to conduct these kinds of attacks. Revolut's breach fits into a well-established pattern.

What Data Was Exposed

Revolut has not yet published a full breakdown of exactly what data was accessed. That is frustrating for customers trying to assess their own risk. Financial services companies are often cautious about disclosing breach specifics while investigations are ongoing, which is understandable but does not help the people whose information is now in someone else's hands.

Given how Revolut operates, the data at risk could include names, email addresses, phone numbers, partial payment card details, and transaction histories. Revolut processes millions of transactions for users across more than 35 countries and has over 45 million customers globally as of mid-2026. Even a partial breach at that scale involves a meaningful number of people.

The future, in 3 minutes a day. The biggest tech story explained every morning, free. Get the briefing →

Customers who use Revolut should check their notifications for contact from the company and be alert for phishing attempts in the coming weeks. Attackers who obtain partial financial data often use it to make follow-up social engineering attacks more convincing.

The Broader Problem for Fintech

Revolut's breach highlights a tension that every fintech company navigating global operations faces. On one side, there is a legal obligation to cooperate with law enforcement quickly, across dozens of different jurisdictions with different processes, languages, and authentication standards. On the other, there is a security obligation to verify that the people making those requests are who they say they are.

Revolut has grown fast. Very fast. The company went from a travel card startup to a banking licence holder across multiple markets in under a decade. Fast growth in regulated industries creates compliance infrastructure that sometimes lags behind operational scale. Whether that is a factor in this breach is not yet clear, but it is a question worth asking.

For regulators, this incident reinforces the argument for a standardised, cryptographically authenticated emergency data request system across the industry. The UK's Financial Conduct Authority and equivalents in the EU have been pushing for stronger data governance frameworks for fintechs. Expect this breach to feature in those conversations.

What Revolut Users Should Do Now

Check your Revolut app and email for any notification from the company about whether you were affected. Enable two-factor authentication if you have not already. Be sceptical of any unexpected communications that reference your Revolut account, especially ones that ask for personal details or click-through links. And monitor your linked accounts for unusual activity over the next few months.

The attackers already have whatever data they extracted. The only variable now is what they choose to do with it.

Sources

More from Future Technology