Revolut Confirms Breach via Fake Government Email Requests
Revolut confirmed it released customer identity data after fraudulent requests from a legitimate government email domain, including passport and driver's license copies. The company called the victim count limited and did not name the agency.

TechCrunch (Jagmeet Singh, 12 September 2026) reported that Revolut confirmed it disclosed sensitive customer information to an unauthorized third party after fraudulent requests sent from a legitimate government agency email domain. The company said customer funds and its own systems were not touched.
This is a company confirmation to TechCrunch plus a customer notification email TechCrunch reviewed. It is not a Revolut platform remote-code exploit, not a funds theft, and not a CISA Known Exploited Vulnerabilities listing.
A spokesperson called it a sophisticated external impersonation scam. The company said a "limited" number of customers were impacted and that those customers were contacted directly. Revolut did not disclose the exact count, did not name the agency, and did not say whether the incident was limited to one market.
The customer notice said the exposed data included identity and contact details (birth date, postal and email addresses, phone numbers) and copies of identity documents, specifically passports and driver's licenses. The notice also said the data may have included verification selfies, account statements, and transaction histories.
Revolut blocked the email address after discovery and alerted the relevant government agency, law enforcement, and regulators. The spokesperson said "Revolut systems and customer funds are unaffected." Crypto researcher ZachXBT posted about the customer email and said the incident appeared targeted at high-net-worth users.
Victim count stays "limited," with no public number. The government agency is unnamed. Later social claims of VIP data dumps and ransom demands have not been confirmed by Revolut, and Help Net Security treats those Monday posts as unverified colour, not as a company statement.
Related identity-document and phishing tape includes IDScan's 150 million-plus license breach, Microsoft passkey lures into Microsoft 365 cloud theft, and the Twitch JeetBot OAuth token leak. None of those incidents is a government-domain impersonation of a KYC desk.
If you run KYC or government-request desks, treat domain-authenticated email alone as insufficient. Require out-of-band verification before releasing passport images or statements, and check whether your Revolut-linked accounts received a direct notice.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free