Revolut confirms customer data breach through fake government requests
- ID
- 23800
- Status
- summarized
- Published
- 12 Sep 2026, 10:40 PM
- Fetched
- 12 Sep 2026, 10:47 PM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 5.5
- Created
- 12 Sep 2026, 10:47 PM
- Tags
- Audience
- developerssaas_foundersstartup_founders
What happened
Revolut disclosed sensitive customer data—including passport copies, driver's licenses, verification selfies, and transaction histories—to an unauthorized third party who submitted fraudulent information requests from a legitimate government agency email domain. Revolut did not disclose the number of affected customers, the specific market, or which government agency's domain was compromised, but stated its systems and customer funds were unaffected.
Why it matters
If you operate a SaaS or fintech handling KYC data, this is a concrete reminder that 'the request came from a .gov email' is not sufficient verification. Builders handling identity documents should implement a secondary verification channel (e.g., callback to a known agency number, case ID validation) before releasing customer PII, especially in markets like Malaysia where digital government services are expanding and spoofing legitimate agency domains is plausible.
Discussion angle
What verification workflow should your team use before responding to any government or law enforcement data request—do you have a documented second-channel check, or would your support team hand over customer passports if the email looked official?