British fintech company Revolut disclosed on September 12, 2026, that unauthorized third parties obtained sensitive customer data—including passports, selfies, transaction histories, and personal information—by sending fraudulent requests impersonating government agencies. The attackers reportedly demanded 10,000 Bitcoin in ransom, though Revolut confirmed customers' funds remained safe.
British fintech Revolut confirmed on 12 September 2026 that a limited number of customers had sensitive information disclosed after an unauthorized third party submitted fraudulent requests using a legitimate government agency email domain. Exposed data included passports, identity documents, and contact information.