Revolut Leaks Passports to a Fake Government Request
Revolut handed strangers copies of passports, verification selfies, and the financial histories of some clients, mistaking fraudulent requests for the official approaches of a government agency. On September 12, 2026, the British fintech confirmed the breach and reported that the emails arrived from the agency’s genuine domain, so they appeared authentic and passed domain verification. TechCrunch was among the first to report that Revolut confirmed the breach stemmed from fake government requests.
What Was Exposed
The set of disclosed details varied from client to client. In its notification, Revolut listed full names, dates of birth, occupations, home and email addresses, phone numbers, copies of passports or driving licenses, and the facial photographs taken during identity verification.
The financial portion of the dossier could include bank statements, IBANs, account status and opening date, an internal wallet identifier, withdrawal details, and the complete transaction history. In certain cases, the attackers obtained Bitcoin transaction data, allowing a real person to be matched with the movement of cryptocurrency.
Biometric Telemetry Stayed Out of Reach
Revolut separately clarified that facial biometric telemetry did not fall into outsiders’ hands. This refers to mathematical templates, liveness-check results, and other parameters the system computes from a photograph. Nevertheless, the selfie itself, together with a passport copy, may still help fraudsters impersonate a client and attempt to pass identity verification at other services.
The Bank’s Servers Were Never Breached
The company found no signs of a breach of Revolut’s infrastructure. By the fintech’s account, the attackers used an unauthorized mail account created directly within the government body’s official domain infrastructure. The correspondence carried valid domain-authentication data, so Revolut staff deemed the requests legitimate and handed over the information sought.
The deception came to light after Revolut separately contacted the agency to verify the requests. Representatives of the government body confirmed that they had not authorized the approaches and did not control the mail address used. The company did not reveal how the outsiders obtained the account, whether they compromised an existing mailbox, created a new address, or exploited an agency employee’s access.
An Attack on Process, Not Servers
The attack struck not at the banking servers but at the procedure for handling official requests. Domain authentication confirms the origin of an email and the integrity of the message, yet not the authority of the particular author nor the legitimacy of the demand. Such a scheme belongs to social engineering, in which the attacker compels an organization to surrender protected information of its own accord.
After uncovering the deception, Revolut blocked the address in its internal systems, alerted the government agency, law enforcement, and regulators, and contacted the affected clients. The company asserts that its banking infrastructure and users’ money were unharmed. There are as yet no confirmed cases of funds being siphoned or accounts being accessed.
An Unknown but Possibly Targeted Scale
Revolut calls the number of victims “limited” but does not disclose the exact scale, the clients’ countries of residence, the date of the data transfer, or the name of the government body. The available information does not confirm that every user of the service received the warning. The company states that it sent personal notifications to those whose details were genuinely disclosed.
The blockchain investigator ZachXBT surmised that the criminals deliberately gathered the data of affluent clients and holders of large cryptocurrency assets. Among the recipients of the notification was Mark Karpelès, the former head of the Mt. Gox exchange. Revolut did not confirm any selection of victims by wealth, so the theory of a targeted hunt for rich users remains, for now, a supposition.
The Danger of Combined Data
The chief peril arises from the combination of documents, contacts, and precise financial history. For targeted phishing, criminals will no longer need to invent a convincing pretext. A fraudster could cite the client’s address, account-opening date, IBAN, passport details, and a real transaction, then ask for a confirmation code, transfer money to a “safe account,” or install an app.
The history of cryptocurrency operations carries a separate risk. Banking records can link an owner’s name to blockchain addresses, reveal the approximate size of assets, and show the habitual timing of withdrawals. Such a link endures for a long time, since public transactions cannot be erased from the blockchain even after changing a bank account or crypto wallet.
What Affected Users Should Do
Recipients of the notification should verify any approaches through the official in-app chat within Revolut, never share access codes, and closely watch their transactions, phone number, and any attempts to sign up for services in their name. Knowing the exact amount of a transfer or passport data can no longer be considered proof that a bank employee is calling. There is as yet no confirmation that the criminals have already used the disclosed information.
Revolut has faced a human-factor attack before. In a previous breach in 2022, attackers used social engineering to gain access to a database and affected the details of roughly 50,150 clients. The new case differs in mechanism and in the set of information. The criminals did not penetrate Revolut’s database; instead, they persuaded employees to compile and send an almost complete client dossier themselves.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.