Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 6, 2026

Revolut data breach: the reported fake government request

Reuters reported that Revolut confirmed disclosing customer data after fake government requests. Italy's government says Revolut reported 680 customers. What is reported, the GDPR and AML rules, and a checklist.

By DiditUpdated
revolut-fake-government-request-kyc-data-2026-cover.png

In short

The reported Revolut data breach was a disclosure made in reply to requests. Reuters reported on 12 September 2026 that Revolut confirmed customer data went to an unauthorised third party after it received fraudulent requests from a legitimate government agency email domain, and quoted a spokesperson saying Revolut's systems were unaffected.[12] Italy's government has since told parliament that a certified email address tied to an Interior Ministry office was compromised, and that Revolut reported providing the data of 680 customers.[1][2]

  • TechCrunch, which reviewed the customer notice, reports identity and contact details and identity document copies; the data "may have also included verification selfies, account statements, and transaction histories".[13]
  • No published regulatory finding or sanction was found in the sources reviewed as of 6 October 2026. The UK data protection regulator told City AM it was assessing a report.[16]
  • Firms under anti-money laundering duties must keep due diligence records for five years after a customer relationship ends.[6][7]

Last reviewed: 6 October 2026 · Not legal advice

Firms subject to anti-money laundering (AML) duties keep a know-your-customer (KYC) file: a copy of the due diligence documents and information they obtained, and records of transactions.[6][7] The file is kept so that authorities can investigate.[6] The reported Revolut data breach shows what can happen when the party asking is not an authority.

No statement on a Revolut-owned channel was found, so Revolut's words appear as quoted by the outlet named.

What happened in the Revolut data breach

On 12 September 2026, Reuters reported that Revolut had confirmed that sensitive customer information was disclosed to an unauthorised third party after the company received fraudulent requests from a legitimate government agency email domain.[12] A Revolut spokesperson told TechCrunch: "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."[13]

Reuters quotes the spokesperson: "Revolut systems and customer funds are unaffected." And on the response: "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators."[12]

Affected customers had been emailed a notice the day before, Friday 11 September, according to BankInfoSecurity, whose publisher reviewed the email.[15] Security Affairs quotes the notice: "As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request."[19]

OutletBasisWhat it reports the notice lists
TechCrunch[13]Reviewed the noticeBirth date, postal and email addresses, phone numbers, passport and driver's licence copies. The data "may have also included verification selfies, account statements, and transaction histories"
BankInfoSecurity[15]Its publisher reviewed the noticeName, date of birth, occupation, contact details, a driver's licence or passport copy, a facial verification selfie, and account statements listing the international bank account number (IBAN)
The Record[14]Notices shared by affected customersBirth dates, postal and email addresses, phone numbers, passport and driver's licence copies, verification selfies, bank statements, IBAN, withdrawal records and transaction histories, including Bitcoin activity

One row per outlet; the lists are not merged.

BankInfoSecurity quotes the notice as adding: "Please note that no biometric facial telemetry data was involved or compromised."[15]

Reuters reported that Revolut described the number of customers as "very limited", and TechCrunch reported that it declined to disclose the agency.[12][13] The figure and the agency came from Italy's government. On 18 September 2026, the Interior Undersecretary told the Chamber of Deputies that Revolut had notified Italy's national cybersecurity agency (ACN) of a possible incident on 12 September, and on 15 September confirmed that it had provided the data of 680 customers, eight of them Italian, and had told them.[1] In the same answer, the government said Revolut reported the compromise of a certified email address (PEC) tied to the Prefettura di Reggio Calabria, a local office of the Interior Ministry.[1]

Note

The Financial Times reported on 15 September 2026, citing a person familiar with the matter, that the email exchanges continued for several months.[17] The sources reviewed do not establish a complete incident timeline.

The law behind it: breach rules and AML record keeping

Under the GDPR, an unauthorised disclosure can be a personal data breach, and Articles 33 and 34 set the notification duties.[3] AML rules explain why the file exists.

A disclosure can be a personal data breach

Article 4(12) of the EU General Data Protection Regulation (GDPR) defines a personal data breach to include the "unauthorised disclosure of, or access to, personal data".[3]

Article 33(1)Regulation (EU) 2016/679

"In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons."

Source: EUR-Lex, Regulation (EU) 2016/679[3]

Article 33(1) of the UK GDPR opens with the same words.[4] Under Article 34, when the risk to people is likely to be high, the controller must also tell them "without undue delay" and "in clear and plain language".[3] Revolut's customer privacy notice names the Information Commissioner's Office (ICO) as its UK authority and Lithuania's State Data Protection Inspectorate (VDAI) for the European Economic Area.[10]

Why the file exists: five years of AML records

Article 40 of the Fourth Anti-Money Laundering Directive (AMLD4) requires the firms it covers to keep a copy of their customer due diligence documents and information for five years after the relationship ends, so that the financial intelligence unit (FIU) and other competent authorities can prevent, detect and investigate money laundering.[6] Regulation 40 of the UK Money Laundering Regulations 2017 sets the same five years as a minimum.[7] From 10 July 2027, Article 77 of the EU Anti-Money Laundering Regulation (AMLR) takes over in the EU.[5]

RuleWhat is keptHow longThen
AMLD4, Article 40 (EU, in force)A copy of due diligence documents and information, and records of transactions5 years after the relationship endsDelete personal data unless national law says otherwise; up to 5 more years[6]
AMLR, Article 77 (EU, from 10 July 2027)The same, not redacted; references may replace copies if the information stays immediately available to competent authorities and cannot be altered5 years after the relationship endsDelete personal data; authorities may require up to 5 more years case by case[5]
Money Laundering Regulations 2017, regulation 40 (UK)A copy of due diligence documents and information, and supporting records of transactionsAt least 5 years after the relationship endsDelete personal data, unless one of the listed exceptions applies[7]
GDPR, Article 5(1)Only what is necessaryNo longer than necessaryProtected throughout[3]

Article 41 of AMLD4 says processing under the directive is subject to the GDPR.[6] Both sets of duties apply to the same record.

What authorities can ask for

One future rule is specific. From 10 July 2027, Article 78 of the AMLR will require the firms it covers to have systems that answer, "through secure channels", enquiries from the FIU or other competent authorities on whether they have or had a business relationship with specified persons in the previous five years, and on its nature.[5] That is one enquiry duty, not a list of everything authorities may obtain.

In the UK, the ICO's guidance, now under review, says: "You must only share personal data that is limited to what is requested and what is reasonable."[9]

Who it affects

In November 2024 the US Federal Bureau of Investigation (FBI) warned of "a trend of compromised US and foreign government email addresses used to conduct fraudulent emergency data requests to US-based companies".[8]

WhoWhy it mattersRule to reread
Banks, payment and e-money firms, crypto-asset service providersThey keep due diligence and transaction records under AML rulesAMLD4 Article 40; AMLR Articles 77 and 78 from 10 July 2027[5][6]
Data protection officersAn unauthorised disclosure can be a personal data breach with notification dutiesGDPR Articles 33 and 34[3]
Banks and financial institutions in ItalyThe Italian data protection authority asked them to check for "anomalous" messages from the same mailboxGarante news item of 18 September 2026; GDPR Article 33[3][20]

Timeline: from the FBI warning to the Italian parliament

  1. 4 November 2024FBI warningNotification on fraudulent emergency data requests.[8]
  2. 12 September 2026ReportedReuters reports that Revolut confirmed the disclosure.[12]
  3. 15 September 2026RegulatorsCity AM carries ICO and FCA statements.[16]
  4. 18 September 2026ParliamentItaly's government confirms a compromised ministry mailbox and 680 customers.[1]
  5. 30 September 2026MinisterThe Interior Minister tells parliament the request should have been verified.[2]

Next fixed date: the AMLR applies from 10 July 2027.[5]

What compliance teams should do now

Security Affairs quotes Revolut's notice as saying the request "carried valid domain authentication credentials".[19] Passing domain authentication does not establish that the requester is authorised to receive customer data: the FBI has described compromised government email addresses being used for fraudulent requests, and recommends contacting "the sender and originating authority" when a request raises doubt.[8] The steps below are my reading, not a regulator's list.

  • Verify each new requester through contact details you found yourself.
  • Share only what is requested and reasonable, and write down why.[9]
  • Require a second reviewer before documents, selfies or transaction histories leave the firm.
  • Track requests by sender, so one mailbox asking about many customers stands out.
  • Rehearse who notifies the supervisory authority: without undue delay and, where feasible, within 72 hours of becoming aware.[3]
  • Delete personal data when the AML period ends and no other legal ground applies.[6][7]

1Log the request

Sender, authority, legal basis and data asked for.

2Call the authority back

Use a number or portal you sourced independently.

The authority confirms the sender and the request

Yes

Disclose the minimum

Only the data requested, after a second review.

No

Stop and escalate

Send nothing and assess earlier replies as a possible breach.

3Keep the evidence

The checks made, the decision and what was sent.

What is still open on 6 October 2026

The latest official word is from 30 September 2026. The Interior Minister told the Chamber of Deputies that the request came from a PEC mailbox named "entilocali", tied to the prefecture and later found to have never been used. He said the company could and should have verified the request with a minimum of diligence, given the mismatch between the data requested and its source.[2] That is a minister's view, not a regulator's finding.

  • An ICO spokesperson told City AM on 15 September: "We can confirm we have received a report and are assessing the information provided." The Financial Conduct Authority (FCA) told City AM it was "engaging with the firm".[16]
  • Italy's data protection authority (Garante per la protezione dei dati personali) said in a news item dated 18 September 2026 that it had asked banks to check for "anomalous" messages from the same mailbox, and its Lithuanian counterpart to confirm whether Revolut had notified it of a breach.[20]
  • VDAI's news page carried no statement on the incident when checked on 6 October 2026.[11]
  • In Italy, a criminal proceeding for unauthorised access to a computer system of public interest is registered with the prosecutor's office in Reggio Calabria. The two parliamentary answers do not say how the mailbox was compromised.[1][2]
  • The sources reviewed do not establish which legal power the requests cited or when Revolut became aware.

Watch out

Reuters reported on 16 September 2026, citing the Financial Times, that a group claiming responsibility had demanded a ransom, and that a Revolut spokesperson said the company had received no direct contact or demand.[18] The group's claims are not confirmed in the sources reviewed.

How Didit helps with the KYC file you keep

Didit does not check whether a request from an authority is genuine, and nothing in Didit's identity verification would have stopped a request like this one. What Didit does sits next to it: it runs the check that creates the document copy and the selfie, and lets you control how long they are kept.

A full KYC check (document, liveness and face match) costs $0.33; see pricing.

Preparing for Article 77: see our AMLR page.

Didit provides

  • Document, liveness and face match checks
  • A retention period you set, from 1 month to 10 years
  • Deletion on demand and EU storage by default

Stays with you

  • The retention period the law requires of you
  • Verifying and answering requests from authorities
  • Breach notification, and the liability

Keep identity data only as long as you must

Set a retention period and delete data when your own clock runs out.

Start freeTalk to us

Key takeaways

  • Reuters reported on 12 September 2026 that Revolut confirmed a disclosure of customer data after fraudulent requests from a legitimate government email domain.[12]
  • Italy's government says Revolut reported providing the data of 680 customers, eight of them Italian.[1]
  • Under the GDPR, an unauthorised disclosure can be a personal data breach. Notification is due without undue delay and, where feasible, within 72 hours of becoming aware, unless a risk to people is unlikely.[3]
  • AML rules make the firms they cover keep due diligence records for five years after the relationship ends.[6][7]
  • Passing domain authentication does not establish that a requester is authorised: verify through a separate channel.[8]

Frequently asked questions

What happened in the Revolut data breach?

Reuters reported on 12 September 2026 that Revolut confirmed sensitive customer information was disclosed to an unauthorised third party after fraudulent requests from a legitimate government agency email domain. Reuters quoted a spokesperson saying Revolut's systems and customer funds were unaffected.[12]

How many Revolut customers were affected?

Italy's Interior Undersecretary told the Chamber of Deputies on 18 September 2026 that Revolut had confirmed providing the data of 680 customers, eight of them Italian. Reuters reported that Revolut's first statement said only "very limited".[1][12]

What data was disclosed?

TechCrunch, which reviewed the customer notice, reports identity and contact details and identity document copies, and says the data "may have also included verification selfies, account statements, and transaction histories". BankInfoSecurity, whose publisher also reviewed it, lists name, occupation, a document copy, a verification selfie and account statements.[13][15]

Which government agency was impersonated?

TechCrunch reported that Revolut declined to disclose the agency. Italy's government told parliament that Revolut reported a compromised certified email (PEC) address tied to the Prefettura di Reggio Calabria.[1][2][13]

Has a regulator fined or sanctioned Revolut over this?

No published regulatory finding or sanction was found in the sources reviewed as of 6 October 2026. The ICO told City AM it had received a report and was assessing it, and the FCA told City AM it was engaging with the firm. Italy's data protection authority said it had contacted its Lithuanian counterpart.[16][20]

Is a disclosure to a fake authority a personal data breach under the GDPR?

It can be. Article 4(12) of the GDPR includes the "unauthorised disclosure of, or access to, personal data" in the definition. Article 33 requires the controller to notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.[3]

How should a firm verify a request from law enforcement?

The FBI recommends contacting the sender and the originating authority when a request raises doubt. Call back through contact details you sourced yourself, and share only what is requested and reasonable.[8][9]

Does Didit prevent fake government data requests?

No. Didit verifies your customers, not authorities. It lets you set how long verification data is kept, from 1 month to 10 years, and delete it on demand.

Sources

  1. Resoconto stenografico, seduta n. 711, interpellanza urgente n. 2-00925, Camera dei deputati, 18 September 2026.
  2. Resoconto stenografico, seduta n. 717, interrogazione n. 3-02906, Camera dei deputati, 30 September 2026.
  3. Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex, Articles 4(12), 5(1), 32, 33 and 34.
  4. UK GDPR, Article 33, legislation.gov.uk.
  5. Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Articles 77, 78 and 90.
  6. Directive (EU) 2015/849 (AMLD4), consolidated text, EUR-Lex, Articles 40 and 41.
  7. Money Laundering Regulations 2017, regulation 40, legislation.gov.uk.
  8. Private Industry Notification 20241104-001 on fraudulent emergency data requests, FBI, 4 November 2024.
  9. Sharing personal data with law enforcement authorities, Information Commissioner's Office, updated 29 September 2023, under review.
  10. Customer Privacy Notice, Revolut, effective 1 January 2025.
  11. News list, State Data Protection Inspectorate of Lithuania (VDAI), checked 6 October 2026.
  12. Revolut confirms sensitive customer data breach after fake government requests, Reuters, 12 September 2026.
  13. Revolut confirms customer data breach through fake government requests, TechCrunch, 12 September 2026.
  14. Revolut handed customer data to fraudsters using government email account, The Record, 14 September 2026.
  15. Revolut Reveals Data Breach Tied to Faked Official Request, BankInfoSecurity, 14 September 2026.
  16. Revolut hackers stole nearly 700 customers' private data, City AM, 15 September 2026.
  17. Hackers say they breached Italian state email to target Revolut 'crypto whales', Financial Times, 15 September 2026.
  18. Revolut says no direct demand received over alleged data breach, Reuters, 16 September 2026.
  19. Revolut exposed KYC data after fraudulent government email passed security checks, Security Affairs, 12 September 2026.
  20. L'Autorità Garante della Privacy e il caso Revolut, Garante per la protezione dei dati personali, news item dated 18 September 2026 (doc. web 10297881).

AML rules require the firms they cover to keep the KYC file. What a firm controls is who can ask for it, how much leaves, and how long it stays. For the verification side of that file, see identity verification with Didit.

Verify identities and control what you keep

Run document, liveness and face match checks with a retention period you choose.

Start freeTalk to us

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page