Revolut leaked sensitive KYC data after government impersonation scam
The fintech giant disclosed identity documents and transaction histories after attackers used a legitimate government email domain to bypass security checks.
Revolut has confirmed a significant data breach after staff fulfilled fraudulent information requests from attackers impersonating a government agency. The incident highlights a critical vulnerability in the company's manual verification processes for legal data requests.
According to a Revolut spokesperson, the company identified a "sophisticated external impersonation scam" where an unauthorized third party used an email account within a legitimate government agency's domain. Because the emails passed standard domain authentication checks, Revolut employees believed the requests were authentic and disclosed sensitive customer information. The fraud was only discovered after the company performed independent verification with the agency in question.
The scale of the leaked data is extensive, encompassing both identity and financial records. Confirmed exposed identity data includes full names, dates of birth, occupations, phone numbers, postal and email addresses, and copies of passports and driver's licenses, as well as verification selfies. Financial disclosures were equally detailed, including account statements featuring IBANs, account status, and opening dates, alongside withdrawal records and full transaction histories, specifically including Bitcoin transactions.
Expansion and Institutional Pressure
This breach occurred in September 2026, a pivotal moment for the fintech firm. Revolut currently serves over 80 million customers globally and is aggressively expanding its international banking footprint. The company recently received conditional approval for a US national bank license and is eyeing a potential IPO with a valuation that could reach $200 billion. For a firm seeking the prestige and regulatory scrutiny of a national bank license, a failure in data governance presents a significant reputational risk.
The Human Element of Security
The incident underscores a growing trend in cybercrime where attackers bypass technical defenses—such as firewalls and encryption—by targeting human workflows. By compromising or utilizing a rogue account within a trusted government domain, the attackers created a "honeypot" of Know Your Customer (KYC) data.
Industry experts note that the combination of government-grade identity documents and detailed financial histories is exceptionally valuable for targeted fraud, identity theft, and extortion. While some reports suggest the incident specifically targeted high-net-worth users, this detail remains a single-source claim.
Next Steps for the Fintech Giant
Revolut has not yet detailed the specific changes it will make to its legal request protocols to prevent a recurrence. Observers will be watching to see if the company implements stricter multi-factor verification for government requests, such as out-of-band confirmation or digital signatures, to replace reliance on email domain authentication. The company's ability to reassure regulators and potential IPO investors regarding its internal controls will be critical in the coming months.