# Revolut Data Breach Exposes Customer Records to Fake Requests

**Published:** 2026-09-12T15:02:27.689Z  
**Topic:** Banking\  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/81e394d6-08a4-46a0-a0b3-1936b243715a

Revolut confirmed a data breach where attackers used fake government emails to steal customer passports, Bitcoin records, and account histories.

Revolut has disclosed that an unauthorized third party obtained sensitive customer information by impersonating a government agency and submitting fraudulent data requests. The breach, which the company says affected a "limited" number of users, exposed personal identity documents, account statements, and detailed Bitcoin transaction histories [1, 3].

| At a glance | |
|---|---|
| Affected Data | Passports, IDs, Bitcoin records, IBANs |
| Scope | Limited, targeted at high-net-worth users |
| System Status | Internal systems and customer funds unaffected |
| Disclosure | Direct notification to impacted individuals |

## How the breach occurred
The incident did not involve a technical compromise of Revolut’s internal systems or a software vulnerability. Instead, attackers utilized a legitimate government agency’s email domain—complete with valid domain authentication credentials—to submit requests that appeared to be lawful demands for information [3]. Revolut’s compliance team, treating the requests as genuine, fulfilled them by releasing a bundle of files that included customer passports, driver’s licenses, verification selfies, and full account histories [2].

While the company has not disclosed the exact number of individuals impacted, the nature of the data suggests a targeted effort. Security researcher ZachXBT noted that the incident appears to have focused on high-net-worth accounts [1]. The exposed information provides a comprehensive profile for potential phishing attacks, as it includes specific Bitcoin withdrawal records, wallet reference numbers, and personal contact details [2, 3]. Revolut stated that it has since blocked the fraudulent email address and alerted law enforcement and relevant regulators [1].

## Operational and market context
Revolut, a London-based fintech with over 80 million global customers, is currently in a period of significant expansion [1]. The firm recently secured banking licenses in France and the UK and received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank, which is expected to launch in the first half of 2027 [1]. This security incident coincides with reports that the company is weighing a public listing that could value the firm at as much as $200 billion, a substantial increase from its $75 billion private valuation in November [1].

Despite the breach, Revolut maintains that its core systems and customer funds remain secure [1]. The company has not confirmed whether the incident was limited to a specific geographic market or identified the government agency whose domain was spoofed [1]. Because the firm is notifying affected customers individually rather than issuing a broad public disclosure, the total scale of the data exposure remains unclear [2].

## What to watch
*   **Public disclosure:** Whether Revolut releases a full recap detailing the number of affected accounts, the specific timeframe of the fraudulent requests, and the internal approval processes that allowed the data release.
*   **Phishing activity:** Any uptick in sophisticated, personalized phishing attempts targeting Revolut users that reference specific account details, such as past Bitcoin transactions or IBANs.
*   **Regulatory response:** Potential inquiries from regulators in the more than 30 countries where Revolut operates as a bank regarding the firm’s verification protocols for legal data requests.

The incident highlights the persistent vulnerability of human-led compliance processes when faced with sophisticated, domain-authenticated impersonation. With the firm preparing for a potential public listing, the effectiveness of its internal controls and its ability to secure sensitive client data will likely remain a focal point for both regulators and prospective investors.

## Sources
1. TechCrunch — [Revolut confirms customer data breach through fake government requests](https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/)
2. 24/7 Wall St. — [Revolut Handed Customers’ Passports and Bitcoin Records to a Fake Government Request. Are You Affected?](https://247wallst.com/investing/cryptocurrency/2026/09/12/revolut-handed-customers-passports-and-bitcoin-records-to-a-fake-government-request-are-you-affected/)
3. CryptoPotato — [Revolut Exposed Passports and Bitcoin Records After Fake Government Request: Report](https://cryptopotato.com/revolut-exposed-passports-and-bitcoin-records-after-fake-government-request-report/)

---
Cite as: TrendWatcher, "Revolut Data Breach Exposes Customer Records to Fake Requests", https://www.trendwatcher.in/article/81e394d6-08a4-46a0-a0b3-1936b243715a
