InfoSec News Nuggets – 09/15/2026
Brief
Revolut Confirms Customer Data Breach Through Fake Government Requests
British fintech Revolut confirmed it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent information requests sent from a legitimate government agency’s email domain, in what the company describes as a sophisticated impersonation scam rather than a system intrusion.
The exposed data included identity and contact details, dates of birth, addresses, phone numbers, copies of passports and driver’s licenses, and in some cases verification selfies, account statements, and transaction histories — though Revolut says a “limited number” of customers were affected and that funds and core systems were unaffected.
