Revolut Data Breach Exposes Passports After Fake Government Requests
Revolut exposed customer identity documents and financial records after fake requests came from a government email domain, though funds remained safe.
Summary
On September 12, 2026, Revolut confirmed it disclosed sensitive customer information to an unauthorized third party that sent fraudulent requests from a legitimate, unnamed government agency email domain. Exposed data included birth dates, postal and email addresses, phone numbers, passports and driver’s licenses, and may have included verification selfies, account statements and transaction histories. Revolut called the affected group limited but disclosed neither its size nor market. ZachXBT shared the customer notification late Friday and said high net worth users appeared targeted.
Revolut blocked the email address, contacted affected customers and alerted the agency, law enforcement and regulators; its systems and customer funds were unaffected. The London fintech has more than 80 million customers and operates as a bank in over 30 countries, with recent expansion in India, Mexico, France and the UAE. Earlier in September 2026, the Office of the Comptroller of the Currency conditionally approved a US national bank that Revolut expects to launch in the first half of 2027. It also recently secured French and UK banking licenses while weighing a listing worth up to $200 billion, compared with its $75 billion private valuation in November.
Positives
- Revolut blocked the fraudulent email address and alerted the government agency, law enforcement and relevant regulators.
- Revolut’s systems and customer funds remained unaffected by the impersonation scam.
- Affected customers were contacted directly after Revolut identified the unauthorized disclosures.
- Earlier in September 2026, the OCC conditionally approved Revolut’s US national bank, expected to launch in the first half of 2027.
- Recent French and UK banking licenses support Revolut’s continuing international banking expansion.
Risks & concerns
- Passports, driver’s licenses, birth dates, addresses and phone numbers were exposed to an unauthorized third party.
- Verification selfies, account statements and transaction histories may also have been disclosed.
- A legitimate government agency email domain gave fraudulent information requests an appearance of authority.
- Revolut has not disclosed the number of affected customers, the impacted market or the government agency involved.
- ZachXBT said the breach appeared to target high net worth Revolut users.