TechNewsReel
Live

Revolut Leaks Customer Data After Falling for Government Impersonation Scam

The fintech giant handed over passports and transaction histories to hackers who used a legitimate government email domain to bypass security.

TechNewsReel Newsroom · September 15, 2026

Revolut has disclosed a significant data breach in which sensitive customer information was handed over to unauthorized third parties. The leak occurred after the company fulfilled fraudulent requests for data sent from a legitimate government agency email domain.

According to a Revolut spokesperson, the company identified a "sophisticated external impersonation scam" where attackers utilized an official government domain to submit requests for information. Because the emails originated from a trusted institutional source, they bypassed standard verification filters, leading Revolut to release private data under the belief that the requests were authentic.

The scope of the exposed data is extensive. Confirmed leaks include full names, dates of birth, phone numbers, and postal and email addresses. More critically, the breach included high-risk identity documents such as copies of passports and driver's licenses, as well as verification selfies. Financial records were also compromised, with attackers gaining access to account statements and full transaction histories, including Bitcoin activity.

Institutional Trust as a Vulnerability

Revolut is currently one of the world's largest fintech firms, serving over 80 million customers globally. The company is in a period of aggressive expansion, having recently received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank. Furthermore, the firm is reportedly weighing a public listing that could see its valuation reach $200 billion.

This incident highlights a dangerous evolution in social engineering. Rather than using spoofed addresses or phishing links, attackers compromised or utilized actual institutional infrastructure to weaponize the trust that private companies place in government agencies. By operating from within a legitimate domain, the threat actors turned a standard compliance process into a delivery mechanism for data theft.

Industry Implications

For the broader financial sector, the breach underscores a critical vulnerability in how legal and regulatory requests are verified. The reliance on email domain authenticity as a primary trust signal is no longer sufficient when government infrastructure itself can be leveraged by bad actors. For the affected users, the combination of government-issued IDs and full transaction histories creates a high risk of targeted identity theft and sophisticated financial fraud.

What Remains Unclear

While Revolut has confirmed the mechanism of the breach and the types of data stolen, the company has not yet disclosed the total number of affected customers. It remains to be seen whether other financial institutions have been targeted by the same impersonation tactic or if this was a bespoke operation targeting Revolut's specific verification workflows.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.