Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to a fraudster who impersonated a government agency, using requests sent through a legitimate government domain to extract identity documents, bank details, and transaction histories. The fintech, which serves tens of millions of customers globally, is calling the episode a “sophisticated external impersonation scam” rather than a system breach, but the practical effect for the people whose passports and IBANs went out the door is the same: their most sensitive personal data is now in the hands of someone who lied to get it.

The incident, first reported by TechCrunch and BleepingComputer, adds Revolut to a growing list of 2026 companies undone not by a hacked server but by a convincing email. Notification letters started landing in customer inboxes on September 11, 2026, a day before the company’s public confirmation. What makes this case worth a closer look is not the size of the number Revolut has released (it hasn’t released one) but the shape of the failure: a company built on identity verification got fooled by someone else’s fake identity.

What Happened: Revolut’s September 2026 Data Exposure

According to Revolut’s own account, relayed to Malwarebytes and the Irish Times, an unauthorized third party sent requests for customer records that appeared to originate from a real government agency’s email domain. The messages carried valid domain authentication, so Revolut’s fraud and compliance teams processed them as they would any lawful request from a regulator or law enforcement body. There was no exploited vulnerability, no malware, and no unauthorized login. A human process approved data that should never have left the building.

Revolut says it caught the pattern, cut off the email address behind the requests, and looped in the impersonated agency along with law enforcement, data protection authorities, and financial regulators. The company has stressed that its core banking systems and customer funds were never touched, a distinction it repeated to multiple outlets including The Register. That’s true as far as it goes, but funds and data are not the same asset. A stolen passport scan and a matching bank statement can do plenty of damage without anyone ever touching a Revolut account balance.

How the Fraudulent Request Slipped Past Verification

The mechanics here matter more than the headline. Revolut, like most regulated fintechs, has a legal-request pipeline for law enforcement and government agencies to demand customer records under warrant, subpoena, or statutory authority. Those pipelines are built to move fast, because delaying a fraud or terrorism investigation carries its own risk. Speed and skepticism pull in opposite directions, and on this occasion speed won.

The attacker didn’t need to breach Revolut’s infrastructure. They needed a mailbox on, or convincingly spoofing, a government domain, and enough procedural knowledge to format a request the way a real one would look. Once that request lands in a queue built to be responsive, a case worker under time pressure is the last line of defense. That is a much thinner line than a firewall.

Why domain authentication alone isn’t proof of legitimacy

Reports describe the messages as carrying valid authentication tied to the government domain, which most security teams would read as a green light. But domain-level authentication protocols only confirm a message came from a mail server authorized to send on behalf of that domain. They say nothing about whether the specific mailbox was compromised, whether an insider misused it, or whether the sender’s identity within that domain is who they claim to be. Security researchers have flagged compromised or spoofed official accounts as a recurring theme in impersonation fraud all year, and this incident fits that pattern rather than breaking new ground technically. The novelty is the target: a neobank holding identity documents for tens of millions of people.

Teams that want to sanity-check inbound “official” requests can start with basic mail authentication lookups before anything else, though these checks would not have caught a request from a genuinely compromised government mailbox:

dig txt example-agency.gov +short
dig txt _dmarc.example-agency.gov +short
dig txt selector._domainkey.example-agency.gov +short

Those three lookups confirm SPF, DMARC, and DKIM records exist and are enforced, which rules out crude spoofing. They do nothing to verify the human on the other end, which is exactly the gap this incident exposed.

What Customer Data Was Exposed

The data set Revolut handed over is unusually complete for a single incident. It spans identity, contact, verification, and financial records, which together give a fraudster nearly everything needed to open credit lines, pass know-your-customer checks elsewhere, or run targeted social-engineering scams against the victims themselves.

Identity and verification records

Exposed identity fields include full name, date of birth, occupation, home address, email, and phone number, according to reporting from TechCrunch and Cybersecurity News. Beyond that baseline, Revolut also disclosed copies of government identity documents, including passports and driver’s licenses, along with the facial verification selfies customers submit during onboarding. That combination, a document photo paired with a live selfie, is precisely what many other platforms use as their strongest identity check. Once it’s out, it can’t be reissued the way a password can.

Financial and transaction records

On the financial side, the exposed data includes IBANs, account status, account opening dates, full account statements, withdrawal logs, and transaction histories. That last category extends to Bitcoin-related activity, including wallet reference numbers tied to customer accounts, a detail multiple outlets including CoinDesk flagged as the incident’s most unusual angle. Pairing a real name and passport scan with a wallet reference number is a meaningful upgrade for anyone running crypto-targeted phishing or extortion campaigns.

Data categoryExposedConfirmed safe
Full name, date of birth, occupationYesNo
Home address, email, phone numberYesNo
Passport / driver’s license copiesYesNo
Facial verification selfiesYesNo
IBANs and account statementsYesNo
Withdrawal logs and transaction historyYesNo
Bitcoin transaction history and wallet referencesYesNo
Account passwordsNoYes
Login credentialsNoYes
Security codes / 2FA secretsNoYes

How Many Customers Are Affected

Revolut has stuck to the word “limited” when describing the scope of the disclosure, and a company spokesperson repeated that description to multiple outlets without attaching a number. A separate report citing the Financial Times, carried by Investing.com, put the figure at 680 contacted customers. Revolut has not confirmed that count itself, so it should be read as a reported estimate rather than an official figure. Several outlets, including Protos, note the incident appears to have concentrated on higher-net-worth accounts, which would explain why a company with tens of millions of users is talking about hundreds of affected people rather than thousands or millions.

That distinction matters for how the story gets read. A breach affecting hundreds of high-value accounts is a very different risk profile than one hitting a random cross-section of users. It suggests the fraudster either requested specific accounts by name or was working from a pre-existing list, which raises its own question: where did that list come from, and is Revolut the only company that got the same fraudulent request?

Timeline: From Request to Public Disclosure

Public reporting places the customer notification emails on September 11, 2026, with Revolut’s confirmation to press following on September 12. Reuters and Yahoo Finance both dated their reports to that Saturday, and the Irish Times published its account two days later on September 14, once UK and Irish outlets had time to seek comment from Revolut’s press office directly. The gap between the underlying request being fulfilled and the public finding out about it has not been disclosed by the company, which is a common pattern in impersonation-driven disclosures: the company often doesn’t know it was fooled until well after the data has already gone out.

Date (2026)EventSource
Prior to Sept. 11Fraudulent requests submitted via spoofed/compromised government domain, data disclosedRevolut, via multiple outlets
Sept. 11Customer notification emails begin going outReporting cited by BleepingComputer
Sept. 12Revolut confirms incident to press; Reuters, TechCrunch, Yahoo Finance publishReuters, TechCrunch
Sept. 12CoinDesk reports on Bitcoin transaction exposure angleCoinDesk
Sept. 14Irish Times, The Register publish follow-up coverage with company statementIrish Times, The Register

Revolut’s Response and Containment Claims

In its customer notification, reported by both TechCrunch and Malwarebytes, Revolut stated that “Revolut systems and customer funds are unaffected.” The company says it blocked the fraudulent email address once the pattern was identified, alerted the government agency whose domain was used, and notified law enforcement, data protection regulators, and financial regulators. Revolut has declined to name the impersonated agency, which limits outside verification of how the domain was used and whether the agency itself was compromised or simply spoofed.

What Revolut has not detailed publicly is any change to its legal-request intake process. For a company built on identity verification as a core product, the more consequential story may not be the data that already left, but whether the internal process that approved the request gets rebuilt with additional out-of-band verification steps before the next request arrives.

Why the Bitcoin Angle Changes the Risk Calculus

Most bank data breaches expose IBANs or statements. Fewer tie a verified real-world identity directly to on-chain wallet activity. CoinDesk’s reporting singled this out because it collapses two kinds of anonymity that crypto users often rely on separately: pseudonymous wallet activity and KYC-verified banking identity. When a passport scan, a home address, and a wallet reference number sit in the same leaked package, the pseudonymity of the wallet stops mattering. Anyone holding that package can potentially trace a person’s crypto holdings back to a name and address, which is a meaningfully different threat than a stolen bank statement alone. It raises the odds of targeted extortion attempts against customers who are known, or assumed, to hold significant crypto balances.

Historical Context: A Bad Year for Impersonation-Driven Breaches

Revolut’s incident lands in a year already crowded with breaches that trace back to a trusted process being fooled rather than a system being cracked open. Shattered.io has tracked several: Florida’s DMV took seven days to disclose a breach that started with a single compromised login, exposing roughly 200,000 records. Trezor’s email breach sent 347,000 phishing messages after an email service provider was compromised. McKesson faced a ShinyHunters claim of 284 million records tied to third-party access rather than a direct network intrusion, and Manchester Airports Group confirmed 8.7 million records exposed after refusing a ransom demand.

None of those four incidents match Revolut’s mechanism exactly, but they share a theme: the weakest point in 2026’s biggest breaches keeps being a trusted channel, whether that’s a login, a vendor, an email provider, or a legal-request pipeline, rather than a raw software exploit. Attackers have noticed that convincing a human is often cheaper and more reliable than finding a zero-day.

Incident (2026)Root causeReported scale
RevolutFraudulent request via spoofed/compromised government domain“Limited,” reportedly ~680 contacted
Florida DMVSingle compromised login~200,000 records
TrezorCompromised email service provider347,000 phishing emails sent
McKessonAlleged third-party/vendor access (ShinyHunters claim)284 million records claimed
Manchester Airports GroupRansomware intrusion, ransom refused8.7 million records

Competitive and Market Impact for Neobanks

Revolut has spent years positioning itself against traditional banks on the strength of its digital onboarding and identity verification, the very system that just failed here. Competitors including Wise, Monzo, and N26 are almost certainly reviewing their own legal-request intake procedures this week, if only to be able to tell regulators and customers they did. Fintech identity verification is a selling point precisely because it promises fewer forms and less friction than a legacy bank branch. An incident that shows the underlying process can be tricked by a well-formatted email undercuts that pitch industry-wide, not just for Revolut.

There’s also a trust cost that’s harder to quantify than a breach-notification number. Revolut built a valuation north of tens of billions of dollars partly on the argument that it does identity and compliance better than incumbents. A story about handing over passports and Bitcoin histories to someone who lied in an email works against that narrative regardless of how few accounts were actually touched.

Regulatory Exposure: GDPR, the FCA, and What Comes Next

Revolut operates under UK Financial Conduct Authority oversight and GDPR-equivalent data protection rules across its European entities, both of which require timely breach notification and can trigger fines tied to global revenue for serious failures. The company says it has already notified data protection and financial regulators, which is the mandatory first step rather than the end of the process. Regulators will want answers to specific questions: how the request was verified, why passport and wallet data were included in a response that a legal request may not have strictly required, and whether comparable requests were received and fulfilled before this one was caught.

Because Revolut has not named the impersonated agency or confirmed a customer count, regulators in the UK, EU, and any other jurisdiction with affected customers may end up doing more of that fact-finding than the company has done publicly so far. That gap between what’s confirmed and what’s reported (via FT/Investing.com’s 680-customer figure) is likely to be the first thing a regulatory inquiry tries to close.

What Affected Customers Should Do Now

Anyone who received a direct notification from Revolut should treat the exposed passport and selfie data as permanently compromised, since neither can be reissued the way a card number can. Practical steps include placing a fraud alert or credit freeze with major credit bureaus, watching for new accounts opened in your name, and being skeptical of any follow-up contact claiming to be Revolut, a bank, or a government agency asking to “verify” the same information again. That last point is not hypothetical: stolen identity documents are frequently reused in follow-on phishing that references the original breach to sound credible. Readers who want a general check on whether their information has surfaced elsewhere can start with a walkthrough on checking whether your data has already leaked online, and crypto holders in particular should review wallet hygiene given the Bitcoin transaction exposure, including the basics covered in this crypto wallet security guide.

Revolut has not announced a dedicated identity-theft protection offer or credit-monitoring service for affected customers as of publication, unlike some other companies that faced comparably sensitive document exposure this year. That could change once the final customer count and regulatory response take shape.

Predictions: Where This Story Goes From Here

  • Expect Revolut to eventually confirm a customer count closer to, or higher than, the reported 680 figure once regulators press for specifics, following the same pattern as other 2026 breaches that started with vague “limited” language.
  • Expect at least one UK or EU regulator to open a formal inquiry into Revolut’s legal-request verification process within the next two to three months, given the FCA’s recent pattern of scrutinizing fintech operational controls.
  • Expect rival neobanks to quietly announce hardened request-verification steps (callback confirmation, in-person or video verification for high-sensitivity requests) rather than admit they lacked them.
  • Expect targeted phishing campaigns referencing this specific breach to appear within weeks, aimed at the higher-net-worth accounts reportedly involved.
  • Expect the “was it the agency or was it Revolut” framing to remain unresolved unless the impersonated agency is named, since neither party currently has an incentive to volunteer that detail.

The Takeaway for Security and Fintech Teams

The technical lesson from Revolut’s disclosure is not new, but it keeps getting relearned the expensive way: domain-level email authentication proves a message’s transport path, not the legitimacy of its sender’s intent. Any organization that processes legal or regulatory data requests by email should treat this incident as a prompt to add an out-of-band verification step, such as a callback to a published agency number, before releasing identity documents or financial histories. For broader context on how 2026’s breach landscape has shifted toward trusted-channel abuse rather than software exploits, see our ongoing security coverage.

Frequently Asked Questions

What data did the Revolut breach expose?

Reported exposed data includes full names, dates of birth, occupations, home addresses, emails, phone numbers, copies of passports and driver’s licenses, facial verification selfies, IBANs, account statements, withdrawal logs, and transaction histories including Bitcoin-related activity and wallet reference numbers.

Were Revolut passwords or login credentials exposed?

No. Reporting on the incident, including coverage from BleepingComputer and Malwarebytes, states that passwords, login credentials, and security codes were not part of the disclosed data.

How many Revolut customers were affected?

Revolut has only described the number as “limited” and has not published an official figure. A report citing the Financial Times, carried by Investing.com, put the number of contacted customers at 680, though Revolut has not confirmed that figure itself.

Was Revolut hacked?

Not in the traditional sense. Revolut says there was no intrusion into its internal systems. Instead, the company disclosed data in response to fraudulent requests sent using a legitimate government agency’s email domain, which it is calling a “sophisticated external impersonation scam.”

Is my Bitcoin at risk after the Revolut breach?

Revolut says customer funds are unaffected, meaning there is no indication that any Bitcoin holdings were directly accessed or moved. The risk reported by outlets like CoinDesk is different: exposed wallet reference numbers combined with verified identity data could make it easier for bad actors to link a real name to on-chain activity for phishing or extortion attempts.

What should affected Revolut customers do?

Customers who received a notification should assume their identity documents are permanently exposed, consider a credit freeze or fraud alert, watch for accounts opened in their name, and be cautious of any follow-up messages asking them to “reverify” information, since these are common in post-breach phishing.

Which government agency was impersonated?

Revolut has not disclosed which agency’s domain was used or spoofed in the fraudulent requests, and outlets covering the story have not independently named it as of this writing.

Could regulators fine Revolut over this incident?

It’s possible. Revolut operates under UK FCA oversight and GDPR-equivalent rules in its European markets, both of which carry penalties for inadequate data protection controls. Revolut says it has notified relevant regulators, but no fine or formal enforcement action has been announced as of publication.