Revolut leaked customer passports and Bitcoin records in government impersonation scam
The fintech giant disclosed sensitive data after scammers used a genuine government email domain to bypass authentication checks.
Revolut has confirmed a data breach in which sensitive customer information was handed over to unauthorized third parties. The leak occurred after the company fulfilled fraudulent data requests that appeared to come from a legitimate government agency.
According to a Revolut spokesperson, the company identified a "sophisticated external impersonation scam" where attackers utilized a legitimate government agency email domain. Because the requests originated from a genuine domain rather than a lookalike address, they passed Revolut's authentication checks. The exposed data is extensive, including full names, dates of birth, occupations, phone numbers, and postal and email addresses. More critically, the breach included copies of passports and driver's licenses, verification selfies, and complete transaction histories, which included Bitcoin records.
The vulnerability of trust
This incident underscores a systemic weakness in how financial institutions verify official data requests. While many firms rely on domain authentication to verify the identity of government requesters, this breach proves that authenticated domains can be compromised or misused by unauthorized accounts. By leveraging a trusted infrastructure, the scammers bypassed the standard security hurdles that typically flag phishing attempts.
Market implications
The breach comes at a sensitive time for the London-based fintech. Revolut currently serves over 80 million global customers and operates as a bank in more than 30 countries. The company is in a period of aggressive expansion into the UAE and India, and on September 2, 2026, it received conditional approval for a US national bank license from the OCC. Furthermore, the company is reportedly weighing a public listing with a potential valuation reaching $200 billion. While Revolut confirmed that its internal systems, login credentials, card numbers, private keys, and customer funds remained unaffected, the loss of high-value identity documents creates a persistent risk of identity theft for the victims.
Next steps
Revolut has since blocked the fraudulent email address and notified the affected customers, as well as relevant regulators and law enforcement agencies. The industry now faces a broader question of whether email-based verification is sufficient for high-stakes data transfers. Observers will be watching to see if Revolut implements more rigorous, multi-factor verification processes for government requests to prevent similar lapses as it pursues its US banking ambitions.