TechNewsReel
Live

Revolut Leaks Customer KYC Data After Falling for Government Impersonation Scam

The fintech giant handed over passports and identity documents to attackers who used a legitimate government email domain to bypass security checks.

TechNewsReel Newsroom · September 13, 2026

Revolut has disclosed a significant data security incident in which sensitive customer information was handed over to an unauthorized third party. The breach occurred after the company fulfilled fraudulent information requests that appeared to come from a legitimate government agency email domain.

According to a Revolut spokesperson, the company identified a "sophisticated external impersonation scam" where attackers utilized a government domain to submit fraudulent requests for data. The resulting leak exposed a wide array of personal details, including full names, dates of birth, postal addresses, email addresses, and phone numbers. More critically, the breach included highly sensitive Know Your Customer (KYC) documents, such as copies of passports, driver's licenses, and identity-verification selfies.

Revolut emphasized that its core systems and customer funds remained secure, noting that the incident was the result of a social-engineering attack rather than a technical failure or a breach of its internal infrastructure.

The Stakes for a Global Giant

This security lapse comes at a pivotal moment for Revolut. The fintech firm currently serves over 80 million customers globally and has recently secured conditional approval for a US national bank. As the company eyes a potential public listing, market analysts have suggested a valuation that could reach $200 billion. For a firm seeking to establish itself as a regulated banking entity in the US, the mishandling of sensitive identity documents presents a significant reputational and regulatory challenge.

A Critical Validation Failure

The incident exposes a systemic vulnerability in how financial institutions validate legal and regulatory requests. By relying primarily on domain authentication—which the attackers bypassed by using a genuine government email domain—Revolut inadvertently provided a comprehensive set of identity data to malicious actors.

The combination of leaked KYC documents and personal contact information creates a high-risk environment for affected users. These assets are prime tools for identity theft, targeted phishing campaigns, and extortion, as they provide attackers with the exact documentation required to impersonate victims across other financial platforms.

Looking Ahead

While Revolut has contained the immediate incident, the breach raises questions about the adequacy of current verification protocols for government-led data requests. Industry observers will be watching to see if the company implements more rigorous, multi-factor verification processes for legal requests to prevent similar impersonation attacks. It remains to be seen if regulatory bodies in the US or Europe will launch formal inquiries into the company's data handling practices following the disclosure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.