TechNewsReel
Live

Revolut Leaks Sensitive Customer Data After Government Impersonation Scam

The fintech giant disclosed passports, selfies, and transaction histories after trusting fraudulent requests sent from a legitimate government email domain.

TechNewsReel Newsroom · September 14, 2026

Revolut has confirmed a significant data breach after employees fulfilled fraudulent information requests sent by attackers posing as government officials. The incident exposes a critical failure in the company's verification process for legal data requests, leaving sensitive customer identity and financial records in the hands of unauthorized third parties.

According to a Revolut spokesperson, the company identified a "sophisticated external impersonation scam" where attackers utilized a legitimate government agency email domain to submit fraudulent requests. Because the emails appeared to originate from an official source, Revolut fulfilled the requests, inadvertently leaking a trove of highly sensitive data. The exposed information includes full names, dates of birth, phone numbers, postal and email addresses, and copies of passports and driver's licenses. Additionally, the breach included verification selfies and detailed financial records, such as IBANs, account statements, and full transaction histories, including Bitcoin-related activity.

The Vulnerability of Trust

This breach was not the result of a traditional system hack or a technical exploit of Revolut's infrastructure. Instead, it was a social engineering attack that exploited the trust placed in official government communication channels. By leveraging a legitimate domain, the attackers bypassed standard security skepticism, leading Revolut staff to hand over data that is typically protected by strict Know Your Customer (KYC) regulations. While Revolut has stated that its systems and customer funds remain unaffected, the human element of the security chain proved to be the weakest link.

Long-term Identity Risks

The nature of the leaked data creates a permanent risk for the affected users. Unlike passwords or credit card numbers, which can be reset or canceled, government-issued identity documents and verification selfies cannot be changed. This makes the victims prime targets for long-term identity theft and sophisticated phishing campaigns. The loss of full transaction histories further compounds this risk, providing attackers with a detailed map of users' financial habits and assets, which can be used to craft highly convincing social engineering attacks or extortion attempts.

Industry Implications

As a global fintech leader with over 80 million customers, Revolut's struggle with basic request verification highlights a systemic vulnerability across the financial sector. Many institutions rely on the perceived authenticity of email domains to process legal requests, a practice that is increasingly dangerous as attackers find ways to compromise or spoof official channels. This incident comes at a sensitive time for Revolut, which is expanding its footprint in the U.S., India, and Europe while eyeing a potential public listing with a valuation that could reach $200 billion.

What Remains Unconfirmed

While the core of the breach is confirmed, the full scale of the impact remains unclear. Reports from Cointelegraph indicate that attackers have threatened to leak the stolen information on a daily basis, though the total number of affected accounts has not been officially disclosed. Industry observers are now watching to see if Revolut will implement more rigorous, multi-channel verification processes for government requests to prevent a recurrence of this impersonation tactic.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.