Children of the Digital Age

Revolut Data Breach: 10 Steps to Protect Your Account

Advertisements

Revolut data breach account security and fraud protection illustration

The Revolut data breach reported in September 2026 is a sharp reminder that account security is no longer only about passwords

Revolut says criminals used a legitimate government-agency email domain to submit fraudulent requests for customer information. The company says its core infrastructure, customer accounts and funds were not hacked. However, sensitive customer data was disclosed to an unauthorised third party. That distinction matters.

This was not a conventional criminal break-in to Revolut’s banking systems. It was an impersonation and social-engineering attack. Criminals exploited the trust attached to an official communication channel. For customers, the biggest danger may now be what happens next.

Around 680 customers are understood to have been affected globally. Twelve Irish customers were reported among them. Revolut has around 3.4 million customers in Ireland. Reported information included names, dates of birth, addresses, email addresses, phone numbers and copies of identity documents. Some affected customers may also have had verification selfies, account statements and transaction histories exposed. That information can make the next scam far more convincing.

What happened in the Revolut data breach?

Revolut said an unauthorised third party used an email account on a legitimate government-agency domain. The criminals then submitted requests for customer information that appeared to be genuine.Revolut processed some of those requests before identifying the fraud. The company says it blocked the address when the incident was detected. It also alerted the government agency, law-enforcement authorities and relevant regulators.

Revolut has stressed that customer funds were not compromised through an intrusion into its systems. But be aware that does not make the Revolut data breach harmless.

Later reports said the attackers demanded $3 million and threatened to release customer information. Revolut told Reuters that it had received no direct ransom demand from the alleged attackers. Customers should therefore concentrate on the risk they can control: follow-on fraud.

Why the stolen information matters

A password can be changed. Your date of birth cannot. Your historical home address may remain linked to you for decades. A passport image, driving-licence copy or verification selfie can also have value to criminals long after the original incident. This is why the Revolut data breach creates a particular social-engineering risk.

A criminal may telephone you and already know:

That information creates credibility. ESET Ireland warned that a fraudster holding several pieces of accurate personal information can sound highly convincing when pretending to represent a bank.

The next line may be:

“Your account has been compromised. We need you to move your money to a safe account.”

There is no safe account. Revolut states that it, other banks, tax authorities and police will not ask customers to move money to another account to protect it. Our guide to protecting personal information online contains further advice on identity theft, phishing and personal-data security. Protecting Personal Information Online

Six Revolut security settings to change now

After the Revolut data breach, customers should review every security control available inside the app. Be aware that occasionally, menu names can change after an app update. Always use the latest version of Revolut.

1. Turn on Wealth Protection

Wealth Protection adds biometric confirmation before larger transfers or withdrawals.

Revolut says Wealth Protection can require biometric authentication for outgoing transfers or withdrawals above the limit selected by the customer.

Why it matters: someone who gains access to your unlocked phone may still face another identity check before moving a large amount of money. Remember that Wealth Protection is another security layer. It does not guarantee that losses cannot occur.

2. Turn on Street Mode

Street Mode adds extra protection when larger transfers happen away from trusted locations.

Revolut says users can select a security delay of 30 minutes, one hour or six hours. After that delay, another biometric confirmation is required before the transfer proceeds. This is particularly useful where a phone has been stolen or someone is being pressured into making a transfer.

Why it matters: Street Mode deliberately adds friction when a high-risk transfer takes place away from somewhere you trust.

3. Use single-use virtual cards for one-off online purchases

Revolut’s single use virtual card creates card details for a transaction and then refreshes them. That means the same card number cannot simply be reused after the purchase. Revolut recommends them for one-off online transactions, particularly when customers have concerns about a merchant storing card details.

Do not use them for:

Why it matters: stolen card credentials become far less useful once those details have changed.

4. Set spending limits on your cards

Revolut allows customers to apply monthly spending limits to individual cards.

Open: Cards → Select card → Settings → Spending limit

Choose a figure that reflects how you normally use that card.

Revolut states that transactions exceeding the selected monthly limit will be declined. You could also maintain a lower limit on a secondary card used mainly for online shopping.

Why it matters: a spending limit can contain the damage if card information is misused.

5. Check payment notifications

Notifications are easy to overlook.

Why it matters: rapid detection gives you the best chance of limiting further unauthorised activity.

6. Review trusted merchants and recipients

This setting needs particular attention.

Revolut allows users to add businesses as trusted merchants. Trusted merchants may not require the same 3D Secure authentication checks for later transactions.

You should therefore periodically review the list.

Revolut allows a previously trusted transfer recipient to be marked as untrusted again. Payments to that recipient will then require stronger authentication. Never approve a merchant or recipient simply because an unexpected warning is inconvenient.

Why it matters: convenience should never become permanent, unnecessary trust.

7. Hide high-value accounts

Revolut now allows customers to hide selected accounts, savings balances or Pockets. The balance disappears from the main account view. Access requires biometric authentication. This may help if someone gains physical access to an unlocked phone.

8. Use Revolut’s call-verification feature

This may become one of the most important protections after the Revolut data breach. Revolut has introduced an in-app banner that helps customers check whether a caller is genuinely Revolut. Open the app while the call is taking place. Revolut says the banner will indicate whether the call is genuine. Revolut also says it will not simply call customers unexpectedly outside the app. Calls are generally arranged through secure in-app communication. Remember caller ID alone proves nothing and phone numbers can be spoofed.

9. Secure the phone itself

After the Revolut data breach, remember that the app is only one security layer. You also need to protect your device.

Use:

Do not share your phone passcode casually. For more general adult cybersecurity guidance, see our Adult Safety resource. Adult online safety and cybersecurity

10. Freeze cards immediately when something looks wrong

Do not spend an hour investigating before taking action. If an unfamiliar card transaction appears, freeze the card first. Then investigate. Contact Revolut through the app. Revolut says customers who suspect fraud should report it immediately using secure in-app support.

What affected customers should do now

Anyone contacted directly by Revolut about the Revolut data breach should take additional precautions.

First, verify the notification inside the app. Do not assume an email or text mentioning the breach is authentic. Criminals may exploit publicity surrounding the incident to send fake “security alerts”.

Second, ask Revolut what information relating specifically to you was disclosed. There is a significant difference between a leaked email address and an exposed passport image.

Third, monitor financial activity closely. Irish customers can obtain their credit information through the Central Credit Register. ESET Ireland has recommended that affected customers consider checking their credit record for activity they do not recognise.

Fourth, consider what action is appropriate if an identity document was exposed. Contact the authority that issued the document and ask what it recommends. Do not assume a replacement document automatically removes every risk associated with the compromised information.

Watch for the scam that comes after the breach

The Revolut data breach provides a textbook example of why leaked information creates continuing danger. While the original incident may be over the exploitation of the data may not be.

A criminal could contact you by:

They may know real information about you. They may even mention the Revolut incident itself. That does not make them genuine. Malwarebytes reported phishing texts appearing shortly after disclosure of the breach, although it said there was no evidence at that stage proving those messages came from the stolen Revolut information. That distinction matters. Do not create a connection where none has been established. But remain alert. One rule cuts through much of the confusion.

Never allow the person contacting you to control the verification process

What the incident tells us about financial cybersecurity

The Revolut data breach highlights something wider than one company. Cybersecurity is not only about malware, passwords and firewalls. It is also about trust. It is about verifying the identity of someone requesting information. It is about confirming that the person using an apparently legitimate communication channel actually has authority to make that request.

The EU’s Digital Operational Resilience Act, or DORA, has applied since 17 January 2025. It creates harmonised requirements covering ICT risk management, incident reporting, resilience testing and third-party technology risks across much of Europe’s financial sector. DORA cannot prevent every deception. Nor can technical authentication alone prove that the person behind an official email account is acting legitimately.

The lesson from this incident is uncomfortable but important. A genuine domain can carry a fraudulent request. An apparently official message can be false. Strong security therefore requires organisations to verify the person, authority and purpose behind sensitive requests.

Advice for parents, schools and families

The Revolut data breach matters to families because app-based banking now sits on the same smartphones used for messaging, social media, gaming and school communication. Young people may also use linked cards, junior banking products or family-managed accounts. Parents should treat financial-security controls much like parental controls. Set them before an incident occurs.

Teach teenagers three rules:

Schools can reinforce the same lessons through digital-safety and financial-literacy education. Children also learn security behaviour by watching adults. If parents click unknown banking links, share passcodes or react immediately to frightening messages, children will often copy that behaviour.

 Our Resources for Parents contain further practical guidance for securing family devices and accounts. Resources for Parents

Families can also use our Video Guides for Parents and Children to start wider conversations about digital risk. Video Guides for Parents and Children

Revolut data breach security checklist

After the Revolut data breach, every customer should spend ten minutes reviewing these protections:

The Revolut data breach did not require criminals to penetrate Revolut’s core banking systems.They exploited trust. Customers should respond by doing the opposite. Trust less. Verify more. Switch on every useful security layer before you need it.

References

RTÉ News, 14–15 September 2026 — Reporting on the incident, the types of information exposed and the reported number of Irish customers affected. RTÉ: Revolut customer data breach

Revolut, 18 September 2026 — Current guidance covering Hidden Accounts, Wealth Protection, Street Mode and call verification. Revolut: New security features

Revolut Help Centre — Current information on virtual cards, spending limits, fraud protection and support.

European Banking Authority / ENISADORA became applicable across the EU financial sector on 17 January 2025.

Children of the Digital Age
Exit mobile version