Revolut Data Breach Exposes Customer Passports and Transaction Histories
Fintech giant Revolut disclosed a data breach after fulfilling a fraudulent government information request, exposing sensitive customer records.
Fintech giant Revolut has disclosed a major data security incident after releasing sensitive customer records in response to a fraudulent information request that impersonated a legitimate government agency, according to reporting across multiple cybersecurity outlets. The breach, which became public on September 11–12, 2026, bypassed conventional network boundaries entirely. Instead of penetrating core servers or mobile applications, an unauthorized actor exploited trust in official email infrastructure, leveraging an account housed within a genuine government agency domain. Because the incoming message carried valid domain-authentication credentials — passing standard checks such as SPF, DKIM, and DMARC — Revolut staff treated the demand as authentic and fulfilled it under the belief that they were cooperating with a lawful public inquiry.
The disclosures have sent shockwaves through the financial and cryptocurrency sectors, particularly given the specific nature and depth of the leaked records. According to notifications received by impacted users and highlighted by on-chain investigator ZachXBT, the exfiltrated dataset included full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. On the onboarding and documentation side, attackers obtained copies of passports or driving licenses alongside the verification selfies submitted during mandatory Know Your Customer checks. Financial data released in the file transfer included IBAN numbers, account statements, withdrawal logs, and exhaustive transaction histories detailing Bitcoin-related activity.
Media additions
To understand how this incident compares to broader systemic threats and previous disclosures impacting digital platforms, the following data illustrates key structural differences in recent major security events:
| Incident / Event | Vector / Method | Primary Exposed Data Categories | Reported Impact / Scale |
|---|---|---|---|
| Revolut Data Leak (September 2026) | Social engineering via fraudulent government email domain | Passports, driver’s licenses, KYC selfies, IBANs, Bitcoin transaction histories | Limited number of users, specifically targeting high-net-worth accounts |
| Odido Data Breach (February 2026) | Vishing phone call to helpdesk, Salesforce CRM pivot | Names, addresses, IBANs, ID document numbers | 6.39 million customers (90 GB of data across 15 million rows) |
| Revolut Incident (September 2022) | Unauthorized third-party access to internal database | Personal, contact, and financial information | 50,150 customers globally |
Despite the severity of the leak, Revolut has maintained that its core IT systems, customer account accessibility, and funds remain fully secure. In statements provided to TechCrunch and other outlets, a company spokesperson categorized the event as a sophisticated external impersonation scheme rather than a traditional network intrusion or malware infection. Upon uncovering the breach, the firm blocked the rogue email address across its internal network, alerted the compromised government agency so that it could secure its internal systems, and notified relevant law enforcement bodies, data protection regulators, and financial authorities.
For individuals seeking to determine whether they were personally impacted, security guides from outlets such as Cryptoticker emphasize that checking for individual notifications or filing a formal subject access request under Article 15 of the General Data Protection Regulation are the only definitive verification methods. Cybersecurity advisors strongly recommend that affected customers avoid clicking email links, refrain from answering phone calls from supposed support agents referencing transaction histories, and conduct all future account verification exclusively within the official business application interface. As financial platforms continue to scale digital asset products, such as Revolut's recent introduction of its EURR stablecoin under European MiCA regulations and its ongoing pursuit of global banking charters, the incident serves as a stark reminder that authentication protocols protecting domain names cannot independently verify the genuine intent or legal authorization of human operators.