The insurance clone
An insurance site claims FCA regulation. The regulator identifies it as a clone firm.
Audience: Consumers buying insurance online
Revolut confirmed that sensitive customer data was disclosed after fraudulent information requests were sent from a legitimate government-agency email domain.
Each step can look routine. The control point is independent verification before sensitive records are released.
The request appears to come through a legitimate government channel.
Confirm identity, legal authority and scope through an independent route.
Sensitive customer records can leave through a normal compliance process.
Banks, fintechs, legal and compliance teams; affected customers as data subjects
For regulated firms, a trusted domain is not enough. Sensitive data requests need independent requester verification, authority checks and escalation paths before records leave the institution.
TechCrunch reported on 12 September 2026 that Revolut confirmed a limited number of customers were impacted after fraudulent information requests were sent from a legitimate government-agency email domain. The Block separately reported that the incident involved KYC and account data, with possible Bitcoin transaction history exposure. The Financial Times later reported that nearly 700 customers were affected and that the UK Information Commissioner's Office had opened an investigation.
This case is based on public reporting and Revolut statements quoted by those outlets. The government agency, exact request documents, affected markets and final regulator findings were not publicly established in these sources. The incident should not be described as customer funds being stolen or Revolut's core systems being compromised unless later evidence supports that.