TechNewsReel
Live

Revolut leaks customer IDs after falling for government impersonation scam

The British neobank handed over identity documents and transaction histories to attackers using a genuine government email domain.

TechNewsReel Newsroom · September 15, 2026

Revolut has confirmed a significant data breach after employees were deceived into handing over sensitive customer information to attackers. The incident underscores a critical failure in internal verification protocols at one of the world's largest neobanks.

According to the company, the breach was the result of a "sophisticated external impersonation scam." Attackers successfully tricked Revolut staff by using a genuine government email domain to request customer data, bypassing standard security checks. The exposed information is extensive, including dates of birth, postal addresses, email addresses, and phone numbers. More critically, the leak includes copies of identity documents such as passports and driving licenses, as well as verification selfies, account statements, and full transaction histories.

The Scale of the Risk

Revolut currently serves over 80 million customers globally, making the potential blast radius of this breach substantial. The nature of the stolen data—specifically the combination of government IDs and verification selfies—creates a high risk of identity theft and synthetic fraud for the affected users. While the company has notified those impacted, the permanent nature of leaked identity documents means the risk to these customers persists long after the initial breach is contained.

Market and Regulatory Pressure

This security lapse arrives at a precarious moment for the British fintech giant. Revolut is reportedly targeting a valuation of up to $200 billion for a potential initial public offering (IPO), a massive leap from its previous private valuation of $75 billion. Such a high-profile failure in data handling is likely to invite intense regulatory scrutiny regarding the firm's data protection protocols and internal governance. For potential investors, the incident raises questions about whether the company's rapid global expansion has outpaced its operational security and compliance frameworks.

What's Next

Revolut has not yet detailed the specific internal failures that allowed a spoofed or compromised government domain to trigger a data release. Industry analysts will be watching for whether the company implements more stringent multi-factor verification for data requests from external agencies. Additionally, while third-party reports have suggested ransom demands and the targeting of high-net-worth individuals, Revolut has not officially confirmed these details. The company's ability to maintain investor confidence ahead of its IPO will depend on its transparency regarding the full scope of the leak and the concrete steps taken to prevent a recurrence.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.