Revolut Confirms September 2026 Customer Data Breach via Forged Law Enforcement Requests
Revolut has confirmed that some customer personal data was exposed after hackers used forged government and law enforcement emergency data requests to deceive its data-request team. Exposed information includes full names, registered email addresses, phone numbers, and some transaction history and account metadata. Revolut said login credentials, passwords, dynamic PINs, and card numbers were not affected, and customer funds and assets remain safe. The company has blocked the attack, notified regulators, and is rebuilding its legal-request review system.
Revolut has confirmed that some customers' personal data was exposed after hackers carried out a fraudulent attack using forged emergency data requests (EDRs) from government and law enforcement agencies. The attackers sent emergency disclosure instructions to the platform's data-request processing team through forged official letters, emails, and electronic credentials purporting to come from legitimate government departments or law enforcement bodies. These forged requests were deceptive in appearance and format, causing internal support and legal compliance staff to misjudge them during verification, and the requests were ultimately processed in accordance with procedure, releasing background data on some accounts. Relevant regulators and data protection authorities have opened investigations.
The leaked data mainly involved basic personal identity information of some affected customers, including full names, registered email addresses, phone numbers, and some transaction history and account metadata. Revolut said users' login credentials, passwords, dynamic PINs, and bank card numbers and other core financial security credentials were not affected, user funds and assets on the platform were unaffected, and the system's underlying encryption architecture was not technically breached.
After internal security mechanisms detected abnormal data flows, Revolut launched its emergency response process, blocked the relevant attack chain, and conducted a comprehensive retrospective audit of all pending and historically backlogged law enforcement assistance requests. The institution has formally reported the incident to data protection regulators and law enforcement agencies in the relevant countries and is cooperating with professional cybersecurity agencies to trace the specific entities or hacker groups behind the forged requests. Revolut said it is comprehensively rebuilding its legal evidence review system, introducing stricter multi-party offline verification mechanisms, and upgrading automated anti-fraud and credential cross-verification processes to counter attacks involving forged government authorization. Affected users have been receiving dedicated security notifications.
Why this event matters
The event has a measured impact on 3 industrys. The strongest current signal is negative for Financial Technology, with intensity 55/100 and 80% confidence over a short term horizon.
Financial Technology
- Direction
- negative
- Intensity
- 55
- Confidence
- 80%
- Horizon
- Short term
Payment Services
- Direction
- negative
- Intensity
- 40
- Confidence
- 70%
- Horizon
- Short term
Diversified Financials
- Direction
- negative
- Intensity
- 35
- Confidence
- 65%
- Horizon
- Medium term
Impact figures are analytical estimates that combine direction, intensity, confidence and event importance. They are not investment advice.