Revolut leaks customer data to fake government requests
Revolut handed customer ID documents, selfies and statements to scammers who sent fraudulent requests from a real government email domain.
By Lena Hart · Published · Updated · 9 min read

British fintech Revolut has confirmed it gave sensitive customer data to criminals who posed as a government agency, TechCrunch reports.
What happened
The attackers sent fraudulent requests for information from a legitimate government agency email domain, so the messages looked like genuine official requests. Revolut processed them and sent the data before spotting the scam. It has since blocked the address and alerted the agency, police and regulators.
Revolut confirmed the breach in a statement issued on Saturday, September 12, 2026, saying it had identified "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information" (TechCrunch). A company spokesperson added: "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators," as quoted by Malwarebytes.
Timeline of disclosure
- Revolut detected the fraudulent requests and began its investigation before going public.
- The company confirmed the breach publicly on September 12, 2026.
- By September 14, notification emails had reached affected customers, and details were being shared with reporters by outside investigators, according to The Register.
- On September 21, further reporting from Information Security Media Group detailed the scope of the data involved.
What was exposed
- Full names, birth dates, occupations, postal and email addresses, phone numbers
- Copies of passports and driving licences used for identity verification
- Verification selfies taken during onboarding — though Revolut has stressed that "no biometric facial telemetry data was involved or compromised," according to its customer notification email reviewed by Bank Info Security
- Account statements, IBANs, withdrawal records and full transaction histories, including cryptocurrency transactions, according to details reviewed by The Register
Revolut says a "limited" or "very limited" number of customers were affected but has not given a precise figure, citing an ongoing investigation and confidentiality obligations. Its systems and customer funds were not affected, and the company has stressed this was a social-engineering attack rather than an intrusion into its own infrastructure.
Blockchain investigator ZachXBT, who said he had seen copies of Revolut's customer notifications, suggested the breach "seems to have been targeted at high net worth users" and separately claimed on Telegram that the self-proclaimed attackers behind the incident had demanded 10,000 Bitcoin, according to reporting by The Register.
Background: who is Revolut?
Founded in 2015 and based in London, Revolut is one of Europe's largest fintech companies, offering digital banking, multi-currency accounts, cryptocurrency exchange, insurance and other financial services through its mobile app. The company says it serves more than 80 million customers across more than 30 countries, and it received approval to launch its UK banking licence earlier in 2026 (Bank Info Security; The Register). The firm has also been expanding into new markets including India, Mexico, France and the UAE.
As a regulated financial institution holding large volumes of identity documents for anti-money-laundering ("know your customer", or KYC) compliance, Revolut is an especially attractive target: a single successful social-engineering attack can yield exactly the kind of verified identity package that is hardest for criminals to otherwise obtain.
Why it matters
This is a growing tactic: criminals compromise or abuse real government or police email accounts to send "emergency data requests" (EDRs). Companies are trained to respond quickly to these, which makes them a powerful way to bypass normal security. Law enforcement and government agencies routinely send legitimate emergency requests asking companies to hand over user data quickly, without a subpoena, in situations involving imminent danger to life — and tech and financial companies are generally incentivized to comply fast rather than risk delaying a genuine emergency. That urgency is exactly what attackers exploit when they gain access to, or spoof, a real official email account.
Security researchers have documented similar abuse of compromised police and government email systems in other high-profile cases over the past few years, where criminals used stolen law-enforcement credentials to request subscriber data from tech platforms such as Apple, Meta and Snap. The Revolut case shows the same technique being used successfully against a major financial institution holding extremely sensitive identity documents.
ID scans and selfies are especially valuable to fraudsters because they can be used to open new bank, credit or telecom accounts in a victim's name, to pass identity checks at other institutions, or to create convincing deepfake verification packages for further fraud. Combined with full transaction histories, the stolen data could also let criminals build detailed financial profiles of victims, making follow-up scams far more convincing.
How the scam technically worked
Rather than hacking into Revolut's own servers, the attackers appear to have compromised, or gained the ability to send mail from, a legitimate government agency's email domain. From that trusted address, they sent requests formatted to resemble standard official data requests that companies receive routinely from regulators and law enforcement. Revolut's compliance team, trained to respond promptly to such requests, processed them without raising a red flag until irregularities were later noticed. Revolut has not disclosed the identity of the agency whose domain was abused, nor which market or markets were affected, and it declined to answer whether the incident was limited to a specific country, according to TechCrunch.
What affected customers should do
- Watch for new accounts or credit applications in your name, and consider a credit freeze with major credit bureaus.
- Expect convincing scam calls that quote your real details — Revolut will never ask you to move money to a "safe account."
- Report lost or compromised passports or licences if advised, so the documents can be flagged with issuing authorities.
- Change your Revolut app password and enable strong authentication if you have not already done so.
- Monitor bank and crypto wallet statements closely for unfamiliar transactions, especially if you hold significant balances.
- Be alert to phishing emails or texts that reference your real account details, birth date or ID numbers — these can make scams feel legitimate.
What readers should do
- If you bank with Revolut, check your email for an official breach notification from the company and read it carefully to see exactly which of your data categories were exposed.
- Do not click links in unsolicited messages claiming to be from Revolut, your bank, or a government agency asking you to "verify" your account.
- Use a password manager and unique passwords for financial accounts, and turn on two-factor authentication wherever it is offered.
- If you received a notification, consider placing a fraud alert or credit freeze with credit reporting agencies in your country.
- Be especially cautious of phone calls that reference personal details accurately — attackers increasingly use breached data to sound credible before asking you to transfer funds.
- Report any suspicious contact that references this breach to Revolut's official support channels and to your national data protection or financial regulator.



