FinTech and banking firm Revolut exposed sensitive customer information, including passport details, selfie authentication photos, and complete transaction history, after a fraudulent request that appeared to come from an official government agency. Customer information requests from a government agency’s genuine email address passed Revolut’s verification process, according to a post by the International Cyber Digest on Twitter. Revolut later stated that the requests were not genuine, and the compromised customers were informed about it on Friday. A limited number of customers were affected, said a spokesperson from Revolut.
Revolut Blocked Fraudulent Requests After Detecting Impersonation Scam
The compromised data included personal identification and contact information such as date of birth, home and email address, and phone numbers, along with copies of identification documents such as passports and driving licenses. The compromised data may also include selfie authentication images, account statements, and transaction history, according to the notification sent out to affected users via email, as reported by TechCrunch.
:bangbang: BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor.
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later… pic.twitter.com/QFlIlUFpxH
— International Cyber Digest (@IntCyberDigest) September 12, 2026
Revolut, however, did not specify how many people were affected. It also did not reveal if the security breach occurred within a particular market alone and did not disclose which government body was involved. “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.
According to the report from TechCrunch, Revolut blocked the email address after realising the scam carried out by the unauthorised third party and notified the appropriate government agency, law enforcement, and regulators, saying that “Revolut systems and customer funds are unaffected.” The incident created a buzz on X, with people criticising the existing practice of mandated information sharing. Marc Zeller posted that he woke up to Revolut leaking all his data. He added, “A sharp reminder that KYC has not delivered any upside, but rather gotten us into trouble.”
In a similar incident in August, Bits of Gold, a cryptocurrency brokerage service, revealed that cybercriminals hacked about 200,000 users’ personal information. They disclosed the data breach incident on Sunday, stating that one hacker managed to gain entry into a third-party data analytics system, thereby gaining access to customers’ names, national IDs, email addresses, phone numbers, IP addresses, bank details, and public wallet addresses.



