grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

Revolut Data Breach: Passports and Transaction Records Exposed

Revolut Data Breach
Published on
September 14, 2026

Revolut has confirmed a data breach after the company sent sensitive customer records to a threat actor posing as a government agency. The request arrived by email from a legitimate government domain and carried valid authentication. Staff processed it as a routine official enquiry, and no system was compromised at any point. The attacker asked for the data through the same channel regulated firms use every day, and the company answered.

The London-based fintech serves more than 80 million customers across over 160 countries, including 800,000 business accounts. It has described the number of affected people only as very limited, and it has notified them directly. The company declined to publish a figure or name the agency whose domain was used. It also declined to say which markets the fraudulent requests touched.

What the Revolut Data Breach Exposed

The records handed over cover far more than basic contact information. Affected customers had their full name, date of birth and occupation disclosed. The package also included postal address, email address and telephone number, along with copies of identity documents. Passports, driver's licences and the facial verification selfies collected at account opening all went out.

Financial records left with the identity files. The attacker received account statements containing IBANs, withdrawal records and complete transaction histories, including Bitcoin activity. That combination hands over a near-complete financial and identity profile of every person named in the request.

A crypto fraud investigator who published one of the customer notifications believes the Revolut data breach hit high net worth users in particular. The company has not confirmed that reading, and it has released no breakdown of who received notices. The claim remains an outside assessment rather than an established fact.

How the Request Passed Every Check

The Revolut data breach began with a request that looked entirely ordinary. Banks and fintechs answer information demands from police, tax authorities and regulators as a matter of routine. Those requests arrive by email, and the first test of legitimacy is the sending domain. A message that passes authentication on a real government domain looks genuine to the mail server and the analyst alike.

That is what happened here. The request came from an unauthorised account operating on the agency's official domain, and the authentication credentials checked out. The compliance team fulfilled it on the reasonable belief that a real agency had asked.

The control that failed in the Revolut data breach was procedural rather than technical. Domain authentication proves a message came from a given domain, but it proves nothing about the person behind the mailbox. It also cannot tell a compliance officer that the case reference attached to the request exists. Out-of-band verification, meaning a call back to the agency on a number the firm already holds, closes that gap.

Why Identity Documents Raise the Stakes

Passwords can be reset within minutes. Passport scans, driver's licences and verification selfies cannot, so they stay valuable to a criminal for years. The people caught in the Revolut data breach have no practical way to invalidate a document image once it circulates.

Those same documents open doors elsewhere. Identity verification across banking, crypto exchanges and telecom providers often rests on a document scan paired with a selfie. An attacker holding both can attempt account takeover at other providers, or assemble synthetic identities that pass automated onboarding.

Full transaction histories add a second layer of risk. They reveal income patterns, counterparties and holdings, which makes targeted social engineering far more convincing. A caller who can recite a recent payment and its exact amount carries an authority no generic scam script achieves.

The Details Revolut Has Not Shared

The Revolut data breach disclosure leaves several important questions open. Without a victim count, nobody outside the company can judge what very limited means in practice. Without the agency name, every other firm that answers requests from that same domain stays exposed and has no way to know it.

The company said it blocked the offending address on detection. It also alerted the relevant government agency, law enforcement, data protection authorities and financial regulators. Regulatory scrutiny is likely to follow, because GDPR obligations apply to any disclosure of personal data to an unauthorised recipient. The method behind that disclosure does not soften them.

The Revolut data breach is also not the first time the firm has notified customers about exposed records. A 2022 incident affected 50,150 people, though that attack followed a conventional intrusion path. The two cases share a victim list and little else.

What Other Firms Should Change

Any organisation that fields official data requests can draw a practical checklist from the Revolut data breach. Verification should not stop at the sending domain. Firms can require requests to arrive through an established portal and call the agency back on a published number. They can also confirm the case reference with a named officer before any file leaves the building.

Dual authorisation adds friction to requests involving identity documents. It also puts a second pair of eyes on a decision that is hard to reverse. Logging matters just as much, because a firm that records which files went to which requester can scope its exposure in hours instead of weeks.

The Revolut data breach exposed a weakness that no patch will fix. Trust in government email domains is a reasonable default, and attackers have now demonstrated how profitable it becomes once nobody tests it. Customers caught up in this incident should expect targeted phishing and impersonation attempts. They should verify any approach about their accounts inside the app, never through a supplied link or phone number.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.