Elias Virtanen
September 15, 2026
12 min read
Revolut has confirmed a data breach that exposed passports, driving licences and financial records after an employee was tricked by a phishing email sent from a domain belonging to a legitimate government agency. The British fintech, one of the world’s largest digital banks by customer count, told Reuters on Saturday, September 12, that an unauthorized third party obtained sensitive customer information through a fraudulent request rather than a direct hack of its systems. According to a Financial Times report cited by Investing.com and Yahoo Finance, roughly 680 customers have been contacted so far.
The incident, first detailed publicly by Escudo Digital on September 14 and corroborated by Reuters, Khaleej Times, Yahoo Finance and on-chain investigator ZachXBT via KuCoin’s news desk, marks the second time in four years that Revolut has had to notify customers about exposed personal data. It lands at a delicate moment for a company that has spent the past two years pushing toward a full UK banking licence and courting institutional crypto customers, a group that appears disproportionately represented among the notified accounts.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What happened in the Revolut data breach
Revolut says the breach did not involve a technical intrusion into its infrastructure. Instead, the company was deceived by a fraudulent data request that appeared to originate from a legitimate government agency email domain, according to Reuters and Khaleej Times reporting from September 12. An employee handling the request released a batch of customer records believing the inquiry came from an authorized public authority. Revolut has described the episode internally and to affected customers as a targeted impersonation scam rather than a breach of its core banking systems, and it maintains that customer funds were never at risk.
That distinction matters for how the incident will be assessed by regulators and security researchers. A breach caused by a compromised server or exploited vulnerability points to a patchable technical flaw. A breach caused by a forged government request points to a process failure in how a financial institution verifies who it is actually talking to before handing over identity documents, a failure mode that is much harder to fix with a software patch and much easier to repeat against other institutions.
Timeline: from the fraudulent request to public disclosure
Coverage from multiple outlets clusters the incident around the same few days in mid-September 2026. Customer breach notifications began going out around September 11, based on reporting from CryptoTicker and Euro Weekly News, both of which cite the notification emails sent directly to affected users. Reuters and Khaleej Times published Revolut’s confirmation to the press on September 12, a Saturday. Escudo Digital’s English-language writeup followed on September 14, and additional analysis pieces from cybersecurity outlets and crypto-focused publications continued through September 15.
Revolut has not published the exact date the fraudulent data request was received or the exact date the records left the company’s systems. What is publicly known is that the disclosure to customers and to the press happened within roughly 24 to 48 hours of each other, a relatively fast turnaround for a financial institution notifying both regulators and account holders about a data incident of this sensitivity.
What data was exposed: passports, selfies and transaction history
The scope of data described across Reuters, Khaleej Times, CryptoTicker, Euro Weekly News and KuCoin’s reporting is unusually broad for a fintech incident. Exposed categories include full names, dates of birth, occupation, home addresses, email addresses and phone numbers. On top of that baseline contact information, the affected records reportedly included copies of passports and driving licences, plus the identity-verification selfie customers submit during onboarding.
Banking-specific data was also included: IBANs, account status and opening dates, wallet reference numbers, account statements and withdrawal records. Several outlets, including KuCoin’s flash note citing ZachXBT and CryptoBriefing, specifically flag complete transaction histories, including Bitcoin activity, as part of the exposed dataset. That crypto dimension is notable because it suggests the affected accounts skew toward customers who use Revolut’s crypto trading features, a smaller and often wealthier subset of its roughly 80 million registered users worldwide.
Reporting is consistent on what was not exposed. Passwords, login credentials and one-time passcodes were not part of the leaked dataset, according to CryptoTicker’s breakdown of the customer notification. Multiple sources, including KuCoin and Euro Weekly News, also note that the biometric facial-recognition templates Revolut uses to match selfies against ID documents were not compromised, only the original selfie image itself.
How many Revolut customers are affected
Revolut’s own public language describes the group as a limited number of customers, a phrase used in its statements to Reuters and Khaleej Times. The more specific figure comes from a Financial Times report, relayed by Investing.com and Yahoo Finance, which puts the number of contacted customers at approximately 680. Revolut has not published an official customer count of its own, and it is possible the final tally shifts as the company completes its internal review.
That figure is small next to Revolut’s overall customer base, but the depth of data per affected account, government ID documents, verification selfies and full transaction histories, makes the per-customer risk considerably higher than a typical breach involving only emails or hashed passwords. Security researchers commenting on the incident, cited by CryptoBriefing and CryptoTicker, have pointed out that a combined government ID and full financial history is close to a complete identity-fraud kit for whoever obtained it.
Revolut’s official response
Revolut’s public position, relayed through its spokesperson to Reuters, centers on three points: the company was deceived rather than hacked, only a limited number of customers were affected, and those customers were contacted directly. The company has also stressed that its systems and customer funds were not affected and that no unauthorized transactions have been linked to the incident
Revolut’s customer notifications, as described by CryptoTicker and Euro Weekly News, lay out which specific data categories were involved for each recipient and explicitly reassure customers that passwords and biometric templates were not part of the exposure. The company has not detailed publicly what process changes it is making to prevent a repeat, such as stricter verification steps for inbound requests claiming to be from government agencies, though outlets including TheCyberSecGuru report that enhanced checks on external data requests are understood to be underway.
Why the fake government email trick worked
The attack vector here is a variant of what security researchers call an emergency data request scam, a technique that has previously hit US tech companies including Apple, Meta and Discord when attackers used compromised or spoofed police and government email accounts to request user data outside the normal legal process. The Revolut case follows the same logic: an email arriving from a domain that actually belongs to a government agency carries far more implicit trust than a request from an unfamiliar address, which is exactly what makes it effective against employees trained to comply quickly with lawful authority requests.
Financial institutions face a structural tension here. Anti-money-laundering and know-your-customer rules require them to respond promptly to legitimate law enforcement and regulatory inquiries, sometimes under legal deadlines. That same obligation creates an opening for attackers who can convincingly impersonate the requesting authority, whether through a compromised government mailbox or a spoofed domain that passes a cursory check. Analysts quoted by CryptoBriefing and TheCyberSecGuru frame this incident as evidence that verification protocols for external legal and government requests, not perimeter security, are the weak point exposed here.
The crypto angle: why high-net-worth accounts are in focus
On-chain investigator ZachXBT, in comments relayed by KuCoin’s news desk on September 12, flagged that the leaked data appears concentrated among higher-value accounts, given the presence of full Bitcoin transaction histories and wallet reference data alongside standard KYC documents. That combination is particularly valuable to attackers running targeted scams: a leaked dataset showing exactly how much crypto a person holds and when they moved it, paired with a scanned passport and a verification selfie, gives a scammer everything needed to run a convincing impersonation or social-engineering attack against that specific individual.
This is a recurring pattern in crypto-adjacent breaches over the past two years: attackers increasingly value exchange and fintech KYC data specifically because it can be cross-referenced with public blockchain activity to identify wealthy targets for follow-on phishing, SIM-swapping or physical extortion attempts. Revolut’s crypto trading arm, which lets customers buy, hold and transact in digital assets alongside traditional banking, appears to have made a subset of its user base a more attractive target than a typical neobank customer would be.
Regulatory exposure: GDPR, the ICO and Lithuania’s DPA
As of this reporting, no regulator has announced a fine or formal enforcement action tied to the September 2026 incident, which is unsurprising given it was disclosed only days ago. Revolut’s regulatory footprint means several authorities have a plausible interest: the UK’s Information Commissioner’s Office, given the volume of UK-based customers and the involvement of government-request verification failures; the Financial Conduct Authority, which oversees Revolut’s UK operational resilience and safeguarding obligations; and Lithuania’s State Data Protection Inspectorate, which licenses Revolut’s EU banking entity and has direct history with the company.
That history matters here. Lithuania’s regulator previously investigated Revolut’s September 2022 breach, characterizing it as a social-engineering incident and confirming Revolut took prompt action to cut off the attacker’s access once the intrusion was discovered, according to reporting from CSHub and Escudo Digital’s Spanish edition. Under GDPR, companies must notify relevant supervisory authorities within 72 hours of becoming aware of a qualifying breach, and given the sensitivity of government ID documents involved this time, both the ICO and Lithuania’s DPA would be expected to open at least a preliminary review even without public confirmation yet.
Not Revolut’s first breach: the 2022 incident and 2026 records-for-sale claim
This is not the first time Revolut has had to disclose a customer data exposure. On the night of September 11, 2022, an unauthorized third party used social engineering to access part of Revolut’s database, exposing the personal data of 50,150 customers worldwide, including 20,687 in the European Economic Area, according to Which? and CSHub reporting drawn from Revolut’s own disclosures and the Lithuanian regulator’s findings. That breach exposed names, emails, phone numbers, postal addresses, partial card data and account activity, but not full card numbers, PINs or passwords, and Revolut said less than 1% of its customer base was affected at the time.
A separate and unrelated claim surfaced in July 2026, when CyberNews investigated a listing for 75 million Revolut records allegedly for sale, containing partial card details, emails, names, phone numbers, addresses, device details and hashed credentials. CyberNews researchers examined sample data but treated the claim as unconfirmed and possibly linked to older, recycled breach data rather than a fresh compromise. That episode is distinct from the September 2026 fake-government-request incident, but taken together, the pattern across 2022, July 2026 and September 2026 shows Revolut’s core technical infrastructure has largely held up while its human and procedural defenses, verifying who is actually asking for customer data, have been tested and beaten more than once.
How Revolut compares to Monzo, Wise and N26 on security
Among Revolut’s closest European neobank peers, none has a comparably large, publicly reported 2025-2026 incident involving government ID documents and full transaction histories. Monzo’s recent public security narrative has centered on fraud prevention tooling and proactive customer alerts rather than a large-scale data exposure. Wise’s public risk discussion has focused on phishing attempts targeting customers directly rather than backend KYC data leaving the company. N26 has faced repeated regulatory scrutiny from Germany’s BaFin over anti-money-laundering controls and compliance processes, but that is a supervisory and governance story rather than a confirmed large data exfiltration event.
That comparison is not necessarily flattering to Revolut’s peers either, since smaller neobanks handle less overall data and face less attacker interest than a platform serving tens of millions of accounts across dozens of countries with an integrated crypto exchange. But it does mean Revolut is currently the neobank most associated in the trade press with large-scale identity document exposure, a reputational category it has now occupied twice in four years.
Revolut breach timeline at a glance
| Date | Event | Source |
|---|---|---|
| Sept. 11, 2026 | Customer breach notifications begin going out | CryptoTicker, Euro Weekly News |
| Sept. 12, 2026 | Revolut confirms breach to Reuters; ZachXBT flags high-net-worth exposure via KuCoin | Reuters, Khaleej Times, KuCoin |
| Sept. 12-13, 2026 | CryptoBriefing, CryptoTicker and Yahoo Finance publish incident breakdowns | CryptoBriefing, Yahoo Finance |
| Sept. 14, 2026 | ~680 contacted customers figure reported, citing Financial Times | Investing.com, Yahoo Finance |
| Sept. 14, 2026 | Escudo Digital publishes English-language incident summary | Escudo Digital |
| Sept. 15, 2026 | Follow-up cybersecurity analysis and customer guidance pieces continue | TheCyberSecGuru, CryptoTicker |
Fintech breach comparison: 2022 vs. 2026
| Detail | September 2022 breach | September 2026 breach |
|---|---|---|
| Attack method | Social engineering, direct database access | Phishing via spoofed government agency email domain |
| Customers affected | 50,150 worldwide (20,687 in EEA) | ~680 (per FT, via Investing.com) |
| Documents exposed | None (contact and partial card data only) | Passports, driving licences, verification selfies |
| Financial data exposed | Partial card data, transaction metadata | IBANs, full transaction history, Bitcoin activity |
| Passwords/funds affected | No | No |
| Lead regulator involved | Lithuania State Data Protection Inspectorate | Not yet publicly confirmed |
Market and reputational impact
Revolut has spent the past several years building toward deeper regulatory legitimacy, including pursuing a full UK banking licence and expanding into wealth management and crypto services for a customer base that has grown past 80 million registered users globally. A repeat data-handling failure, even one framed as a small-scale impersonation scam rather than a systems hack, complicates that narrative at a moment when Revolut is trying to position itself as a trusted institution rather than a scrappy fintech challenger.
The financial exposure from the incident itself is likely to be limited given the relatively small number of affected accounts, but the reputational and regulatory cost is harder to bound. Every fintech pursuing a banking licence or a public listing has to demonstrate operational resilience to regulators and institutional partners, and a second publicly disclosed data-handling failure in four years, even a small one, is the kind of detail that shows up in due diligence conversations well beyond the 680 customers directly notified.
What affected Revolut customers should do now
- Check for a direct notification email from Revolut confirming whether your account was among those affected, and treat any request to “verify” your account via a link in an unexpected email with suspicion.
- If your passport or driving licence was exposed, contact the issuing authority to ask about fraud-monitoring options and consider flagging the document as potentially compromised with relevant identity-protection services.
- Enable additional account monitoring inside the Revolut app and watch for login attempts or device changes you do not recognize, even though Revolut says passwords were not exposed.
- Be alert to follow-up phishing attempts that reference real personal details from the leak, since attackers commonly use breached data to make scam messages more convincing.
- Crypto-active users should treat wallet addresses and transaction history as exposed and stay alert for targeted scams referencing specific past trades or balances.
Predictions: where this goes next
- Expect Lithuania’s State Data Protection Inspectorate and the UK ICO to open at least preliminary inquiries given the sensitivity of the exposed government ID documents, mirroring the regulatory path taken after the 2022 breach.
- Revolut will likely publish additional detail on process changes for verifying government and law-enforcement data requests, similar to how other tech companies tightened emergency-request verification after being hit by the same scam technique.
- Watch for individual targeted phishing or extortion attempts against the roughly 680 notified customers over the coming weeks, particularly those with visible crypto holdings.
- Competitor neobanks, including Monzo, Wise and N26, are likely to face renewed questions from customers and journalists about their own government-request verification procedures in the wake of this story.
- Expect scrutiny of Revolut’s banking licence ambitions to intensify modestly, though a single limited-scope incident is unlikely on its own to derail licensing discussions already in progress.
Frequently asked questions
What exactly happened in the Revolut data breach?
Revolut confirmed that an employee was deceived by a fraudulent data request sent from an email domain belonging to a legitimate government agency, resulting in sensitive customer information being disclosed to an unauthorized third party. Revolut says its systems were not hacked and no funds were affected.
How many Revolut customers were affected by the September 2026 breach?
Revolut describes the group as a limited number of customers. A Financial Times report, cited by Investing.com and Yahoo Finance, puts the figure at approximately 680 contacted customers.
What personal data was exposed in the Revolut breach?
Reported categories include full names, dates of birth, occupation, home addresses, emails and phone numbers, plus copies of passports and driving licences, identity-verification selfies, IBANs, account statements, withdrawal records and complete transaction histories including Bitcoin activity.
Were passwords or funds stolen in the breach?
No. Multiple outlets report that passwords, login credentials, one-time passcodes and biometric facial-recognition templates were not part of the exposed data, and Revolut says no customer funds were affected.
Has Revolut had a data breach before?
Yes. In September 2022, a social-engineering attack exposed the personal data of 50,150 customers worldwide, including 20,687 in the EEA. A separate, unconfirmed claim about 75 million records for sale was investigated by CyberNews in July 2026 and treated as unverified.
What should I do if I was affected by the Revolut breach?
Check for a direct notification from Revolut, watch for follow-up phishing attempts referencing your real personal details, enable extra account monitoring, and consider contacting the relevant document authority if your passport or driving licence was exposed.
Will Revolut face regulatory fines over this breach?
No fines or formal enforcement actions have been publicly announced as of this reporting. Given the sensitivity of the exposed documents, regulators including the UK ICO and Lithuania’s State Data Protection Inspectorate are expected to review the incident.
How does this compare to breaches at other fintechs like Monzo, Wise or N26?
None of Revolut’s closest neobank peers has a comparably large, publicly reported 2025-2026 incident involving government ID documents and full transaction histories, making Revolut currently the neobank most associated with this type of exposure.
