TechNewsReel
Live

Revolut Leaked Passports and Bitcoin Data via Fake Government Requests

A sophisticated social engineering attack tricked the fintech giant into handing over sensitive KYC and financial records by impersonating a government agency.

TechNewsReel Newsroom · September 14, 2026

Revolut has confirmed a data breach after staff mistakenly disclosed sensitive customer information to an unauthorized third party. The leak occurred when attackers used a legitimate government agency email domain to submit fraudulent information requests, effectively bypassing standard domain verification processes.

According to a Revolut spokesperson, the company identified a "sophisticated external impersonation scam" where attackers operated within a trusted government domain. This led Revolut employees to believe the requests were official. The breach was discovered only after the company independently verified the requests with the agency, at which point Revolut blocked the email address and began notifying affected users.

The scale of the exposed data is extensive, encompassing both identity and financial records. Confirmed leaked information includes full names, dates of birth, occupations, phone numbers, and home and email addresses. Most critically, the breach included copies of passports and driver's licenses, often accompanied by KYC selfies.

Financial data leaked alongside these identities included bank statements, IBANs, account statuses, and internal wallet identifiers. The leak also exposed complete transaction histories, specifically including Bitcoin data. This combination of data is particularly potent, as it links verified real-world identities to specific blockchain addresses.

A Breach of Process

This incident represents a social engineering attack on internal processes rather than a technical failure of the company's servers. Revolut stated that its core infrastructure remained secure and customer funds were not affected. However, the event highlights a recurring vulnerability for the fintech firm; in 2022, a similar social engineering attack targeting an employee exposed the data of approximately 50,150 customers.

Industry Implications

Security experts warn that this breach is dangerous because it pairs government-grade identity documents with precise financial and cryptocurrency histories. By linking real-world identities to specific blockchain addresses, attackers can permanently compromise user privacy. Furthermore, the possession of passports and transaction logs allows bad actors to conduct highly convincing, targeted phishing attacks against victims, who may be targeted based on their specific asset holdings.

What's Next

While Revolut has mitigated the immediate threat by blocking the fraudulent email, the permanent nature of the leaked identity documents means affected users remain at risk of identity theft. Industry observers are now watching to see if Revolut will implement stricter multi-channel verification for government data requests to prevent similar impersonation scams in the future.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.