Revolut Data Breach: Fake Government Email Exposes Customer Passports and Crypto History

Revolut Confirms Data Breach via Fake Government Requests

British fintech Revolut has confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The breach, which came to light on September 12, 2026, has exposed identity documents, contact details, and financial histories of a limited number of customers, according to a notification emailed to affected customers and reviewed by TechCrunch.

The exposed data includes customers' full names, dates of birth, occupations, postal and email addresses, and phone numbers. It also includes copies of identity documents such as passports and driver's licenses, as well as verification selfies submitted during onboarding. Financial data compromised in the incident includes account statements with IBANs, account statuses, opening dates, wallet reference numbers, withdrawal records, and complete transaction histories—including Bitcoin activity.

A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. However, Revolut declined to disclose the exact number of affected individuals, whether the incident was limited to a specific market, or which government agency was involved. The company stated that its systems and customer funds were unaffected.

How the Attack Unfolded

According to Revolut's notification, the incident occurred when an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information. The request originated from an unauthorized email account created directly within an official government authority's domain infrastructure. The communication carried genuine domain authentication credentials, leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request.

Once Revolut discovered the scam, it blocked the email address, alerted the relevant government agency, law enforcement, and regulators. The company emphasized that this was a “sophisticated external impersonation scam” and that no traditional hacking methods—such as server breaches, malware, or password cracking—were involved. Instead, the data was handed over by employees who believed they were complying with an official request.

Key Data Categories Compromised

Why This Matters: The Stakes for Customers and Revolut

The breach raises significant concerns about identity theft and targeted attacks, particularly for high-net-worth individuals. Well-known crypto security researcher ZachXBT posted about Revolut's email to affected customers late on Friday, noting that the incident appeared to have been targeted at high net worth users. Marc Zeller, founder of the now-defunct Aave Chan Initiative, was one of the customers affected by the leak. “Woke up to all my data leaked by Revolut. Sharp reminder that KYC hasn't produced meaningful upside and has put many in harm's way,” he posted on social media channels.

The timing of the breach is particularly problematic for Revolut, which has more than 80 million customers globally and operates as a bank in more than 30 countries. The fintech recently expanded its presence in markets including India, Mexico, France, and the UAE. Earlier this month, the U.S. Office of the Comptroller of the Currency granted conditional approval to Revolut to set up a national bank in the country, expected to launch in the first half of 2027. The incident comes as Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November.

Background of Security Incidents

This incident is not isolated. It comes weeks after a threat actor advertised 75 million alleged Revolut records on a cybercrime forum for $500—a claim Revolut disputed after finding no indicators of compromise and no valid identifiers in the samples. Months earlier, a former employee allegedly tried to extort a customer by threatening to leak KYC data unless paid in cryptocurrency. Additionally, a fraud wave in Jersey saw 75% of scam reports over four weeks involve Revolut accounts, with roughly £180,000 lost.

Broader Implications: KYC Under Fire

The breach has fueled a growing global backlash against mandatory Know Your Customer (KYC) regulations. Critics argue that centralized collection of sensitive identity documents creates attractive targets for attackers and puts users at risk. The incident follows other high-profile leaks, including a 153 million driver's license leak, that have intensified calls to rethink KYC practices.

In the crypto community, the exposure of complete Bitcoin transaction histories is particularly alarming. Unlike traditional banking data, blockchain transactions are immutable and public, meaning that once a wallet's identity is linked to a person, their entire financial history can be traced. For high-net-worth individuals, this could lead to physical attacks—so-called “wrench attacks”—where criminals coerce victims into transferring funds.

What Customers Should Do

Affected customers have been notified directly by Revolut. Those who have not received a notification cannot assume they are unaffected; the company has not published a public list. Customers can verify whether their data was compromised by checking their email for a notification from Revolut or by submitting a Subject Access Request under Article 15 of the General Data Protection Regulation (GDPR).

Revolut has stated that credentials, passcodes, and biometric templates behind facial recognition were not exposed. This distinction matters: an attacker who never had your password cannot be locked out by changing it. However, the exposed data is more than sufficient for identity theft, phishing, and social engineering attacks. Affected individuals should monitor their accounts for suspicious activity, consider freezing their credit, and be vigilant against unsolicited communications referencing personal details.

Regulatory and Industry Response

Revolut has alerted relevant government agencies, law enforcement, and regulators. The government agency whose domain was exploited has been informed that an unauthorized account is operating within its infrastructure. The company has not disclosed which agency was involved, citing the ongoing investigation.

This incident highlights a sophisticated attack vector: rather than exploiting technical vulnerabilities, attackers exploited trust in official communications. Financial institutions and government agencies will need to reassess verification protocols for information requests, particularly those involving sensitive customer data. Multi-factor authentication for internal requests and stricter verification of government correspondence may become standard.

As the investigation continues, Revolut faces scrutiny over its data handling practices and the potential impact on its planned U.S. expansion and public listing. For customers, the breach serves as a stark reminder that even robust security measures can be circumvented by social engineering. The incident underscores the need for vigilance and the importance of understanding what data financial institutions hold—and how they protect it.

Comments