Revolut sent passports and bank statements to a fake state agency
Revolut handed ID documents, verification selfies and transaction histories to a scammer posing as a government agency. Nothing was hacked: the attack came through the channel used for lawful data requests.

Revolut has emailed some of its customers to tell them a data breach affects them. The incident was reported on 14 September 2026 by Bleeping Computer, the only source available so far: neither the number of people affected nor the identity of the impersonated agency is public. The fintech, which claims more than 80 million customers across more than 160 countries and regions, including 800,000 businesses, was not hacked. It handed the data over itself.
A request from authority that cleared the technical checks
The request for personal information arrived by email, from a government agency’s domain. In the message sent to affected customers, Revolut explains that the communication carried valid domain authentication credentials, and that it was therefore handled in the reasonable belief that it was a genuine request.
That is the part worth your attention. The usual technical checks — the ones that let a mail server tell a legitimate sender from a crude forgery — answered exactly as designed. What gave way was the process by which a financial institution handles requests from the authorities: a procedure built on the trust granted to a sender, and one that a domain check is not enough to protect. There is no software vulnerability to fix here, and no patch to deploy.
An inventory of what went out the door
The list given to affected customers is broad. It covers identity details — full name, date of birth, occupation — contact details — postal address, email address, phone number — and verification documents: copies of your identity papers, passport or driving licence, along with facial verification images, the selfies requested when you open an account as part of know-your-customer checks.
Then comes the financial side: account statements including IBAN numbers, withdrawal histories and the complete transaction history, bitcoin transactions included. Identity verification data cannot be revoked the way a password can: a copy of a passport stays valid until the document expires.
Still no figure for how many people
Revolut told Bleeping Computer that the incident affects a limited number of customers, while declining to give an exact figure. ZachXBT, an investigator specialising in crypto fraud, estimated over the weekend that the leak, probably small in volume, appeared to target high-net-worth users — an assessment that remains, for now, that of an outside observer.
The company says it blocked the address as soon as it was detected and alerted the government agency concerned, law enforcement, and both data protection and financial regulators. It adds that its systems and its customers’ funds are unaffected, which is accurate and says nothing about what becomes of the documents that were sent.
The second incident made public in four years
Revolut had already disclosed a data breach in September 2022: attackers took the personal, contact and financial information of 50,150 customers. The scenario then was the familiar one — data stolen. This time it was requested, and supplied.
A bank can encrypt its databases, segment its networks and audit its code, and it will still have to keep one door open to the state. That door has now shown that it, too, is an attack surface.
Sources (1)
- Revolut discloses data breach exposing financial info, passportsbleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


