Revolut fake government-request disclosure (2026): what to check

Updated Corrections

October 3, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

Revolut says it disclosed some customer information in response to requests from an impostor posing as a government authority. According to Malwarebytes’ reporting, the company described a limited group of affected customers and said its systems and customer funds were not compromised by the incident.

What was reported

Reported data categories include identity and contact details, copies of identification, verification selfies and account or transaction records. The exact combination varies by recipient. Revolut has contacted affected customers; this summary does not assign a confirmed total or assume that all customers were involved.

Keep the individual notification for the categories applicable to you. A disclosure of documents is different from proof that an account was taken over or funds were stolen.

Sources

What to do

  • Open the Revolut app yourself and use its official support channel to verify any notice or unfamiliar activity.
  • Review transactions, linked devices and account changes. Report anything you do not recognize through official support.
  • Be cautious about unexpected “security checks,” refunds or document-replacement messages. Do not share passwords or one-time codes, install remote-access software, or transfer funds because someone contacts you unexpectedly.
  • Follow the notification’s document-specific guidance. Use the issuing authority’s official website for questions about an exposed ID.
  • If someone uses your identity, follow recovery guidance for your country. For U.S. residents, IdentityTheft.gov and FTC credit-freeze guidance explain relevant steps.

Where Delist fits

A free Delist scan checks separate sources of personal-data exposure. Delist does not inspect Revolut’s records, establish whether you were in this incident, reverse transactions or erase leaked files. Paid listing-removal work requires separate authorization.

This summary is compiled from public reporting available when this page was last updated. Confirm your own exposure and any assistance offer with Revolut. Inclusion is not an allegation of wrongdoing or negligence.

Was this a compromise of Revolut’s banking systems?

According to Malwarebytes’ reporting of the company’s statement, the incident involved disclosure in response to an impostor’s government request. Revolut said its systems and customer funds were not compromised. This page does not assign a confirmed affected-person total.

Frequently asked questions

Is this the same incident as the DriveWealth broker breach?

No. This page covers the reported fake government-request disclosure. The linked DriveWealth page covers a separate broker-system incident; do not combine their counts or data categories.

How should I verify a notification?

Open the Revolut app yourself and use its official support channel. Keep the notification for your specific data categories, and do not share one-time codes or transfer funds because someone contacts you unexpectedly.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.