TechNewsReel
Live

Revolut leaked customer identity documents in government impersonation scam

The fintech giant handed over sensitive KYC data after attackers used a legitimate government email domain to bypass security filters.

TechNewsReel Newsroom · September 15, 2026

Revolut has confirmed it disclosed sensitive customer data to scammers who successfully impersonated a government agency. The breach occurred after attackers used a legitimate government email domain to submit fraudulent information requests, which the company fulfilled before detecting the scam.

According to reports from Cybernews and Yahoo Finance, the breach affected nearly 700 clients. The exposed data included high-value identity documents such as passports and driver's licenses, alongside birth dates, phone numbers, occupations, and postal and email addresses. Further confirmed details indicate that the leak also included account statements, IBANs, verification selfies, and Bitcoin transaction histories. Among those impacted was Mark Karpelès, the former chief executive of Mt Gox.

A failure of verification

This incident marks a shift from traditional system hacks, as it was a social engineering attack targeting Revolut's internal data request processes. By utilizing a legitimate government agency email address, the attackers bypassed standard trust filters that typically flag external requests.

This event follows a period of heightened scrutiny for the fintech firm, which serves over 80 million retail customers. In July 2026, an attacker claimed to be selling 75 million Revolut records, a breach the company denied at the time. While the current incident affected a significantly smaller number of users, it highlights a persistent vulnerability in the company's external communications.

Industry implications

The breach demonstrates a critical vulnerability in how financial institutions verify government data requests. Because the attackers operated from a trusted domain, they gained access to Know Your Customer (KYC) data—the gold standard for identity thieves. This type of information is particularly dangerous as it can be used for long-term identity theft, financial fraud, and extortion, far exceeding the risk of a simple password leak.

Response and recovery

Revolut stated that its core systems and customer funds remain unaffected. "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators," a Revolut spokesperson said.

Industry observers will now be watching whether other fintechs are susceptible to similar domain-based impersonation scams. The incident raises urgent questions about whether relying on email domains is sufficient for verifying government requests, or if a more robust, multi-factor authentication process for data sharing is required to protect sensitive user identity documents.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.