UK Independent. Sourced. Primary. · Est. 2024
Home News Revolut handed customer passports to a fake government request
News

Revolut handed customer passports to a fake government request

Revolut confirmed on 12 September 2026 that it disclosed customer passports, verification selfies and full transaction histories after fraudulent requests arrived from a genuine government email domain.

CT
Chandraketu Tripathi
Finance Editor, Kaeltripton
Published 13 Sep 2026
Last reviewed 13 Sep 2026
✓ Fact-checked
A person checking their phone at a kitchen table in a UK home

Illustration. AI-generated image, not a photograph of the people or events described in this article.

Advertisement
BANKINGUpdated 13 September 2026

Revolut confirmed on 12 September 2026 that it released customer identity documents, verification selfies and full transaction histories to an unauthorised third party that sent requests from a real government agency email domain. It says a limited number of customers were affected.

TL;DR · LAST REVIEWED 13 September 2026

  • Revolut released identity documents and transaction histories to a fraudulent request, confirmed 12 September 2026
  • The request came from a real government agency email domain and passed authentication
  • Data included passports or driving licences, verification selfies, IBANs and full transaction history
  • Revolut says systems were not breached, funds are safe, and a limited number of customers are affected

What Revolut says was disclosed

IdentityFull name, date of birth, occupation
ContactPostal address, email address, telephone number
VerificationPassport or driving licence copy, onboarding selfie
FinancialIBAN, account status and opening date, withdrawal records
TransactionsFull transaction history, including Bitcoin activity
Not involvedBiometric facial telemetry, per Revolut

Source: Revolut customer notification, as reported

KEY FACTS

  • Revolut confirmed the incident on 12 September 2026 after TechCrunch reported it.
  • An unauthorised third party submitted fraudulent requests for customer information from an email address on a legitimate government agency domain, not a lookalike address, and the messages passed Revolut's authentication checks.
  • Revolut described it as a sophisticated external impersonation scam.
  • The disclosed data included full name, date of birth and occupation.
  • It also included postal address, email address and telephone number.
  • It included copies of identity documents, meaning passports or driving licences, and the facial verification selfie submitted at onboarding.

What happened and what Revolut has confirmed

Revolut confirmed on 12 September 2026 that it released customer identity documents, verification selfies and full transaction histories to an unauthorised third party. The requests arrived from an email address on a real government agency domain and passed the company's authentication checks. Revolut says a limited number of customers were affected and that it contacted them directly.

The confirmation followed reporting by TechCrunch, which published details of the incident on the same day. According to that reporting, an unauthorised third party submitted fraudulent requests for customer information, and those requests were answered. Revolut has characterised the episode as a sophisticated external impersonation scam, a description that places the failure at the point where an outside party successfully presented itself as a legitimate authority rather than at the point where an intruder defeated a technical control.

The distinction matters for how the incident is understood. This was not a case of an attacker breaking into Revolut's systems, and Revolut does not describe it that way. The company says its core systems, its mobile app and customer accounts were not compromised. Instead, information left the organisation through a request channel that was working as designed, answering a party that should not have been answered. The data disclosed was therefore released rather than extracted, which is a different category of event with different implications for both the company and the customers involved.

Revolut has not named the government agency whose domain was used. It has also not published a figure for how many customers were affected, saying only that the number is limited and that those customers were contacted directly. The absence of a number means the scale of the incident remains, for now, a matter of the company's own characterisation rather than a published count.

Exactly which categories of data were disclosed

The disclosed data spanned identity, contact, verification and financial categories. It included full name, date of birth and occupation, postal address, email address and telephone number, copies of identity documents such as passports or driving licences, the facial verification selfie submitted at onboarding, account statements with IBAN, account status and opening date, wallet reference numbers, withdrawal records and full transaction history including Bitcoin activity.

Taken together, the categories form a package that is unusually complete. Identity documents and a verification selfie establish who a person is. Contact details establish how to reach them. Account and transaction records establish how they behave financially and with whom. Each category has its own uses to a fraudster, and the combination is more valuable than the sum of its parts because it allows a convincing approach to be built around verified personal detail.

The inclusion of full transaction history is notable in its own right. Statements and transaction records reveal income patterns, regular payments, counterparties and spending habits. Where Bitcoin activity is included, the record extends to holdings and movements in a asset class that is otherwise pseudonymous. A party holding that record alongside a passport copy and a selfie holds material that would ordinarily be difficult to assemble from separate sources.

Revolut has drawn a specific distinction on the biometric question. It says no biometric facial telemetry data was involved or compromised, separating the selfie image from the derived biometric data used to authenticate a face. The selfie is a photograph. The telemetry is the mathematical representation generated from it. Revolut's position is that the photograph was disclosed and the derived data was not, and it has stated that distinction explicitly rather than leaving it to inference.

What Revolut says was disclosed
CategoryDetails
IdentityFull name, date of birth, occupation
ContactPostal address, email address, telephone number
VerificationPassport or driving licence copy, onboarding selfie
FinancialIBAN, account status and opening date, withdrawal records
TransactionsFull transaction history, including Bitcoin activity
Not involvedBiometric facial telemetry, per Revolut

Source: Revolut customer notification, as reported

Why a request from a real government domain defeated the checks

The fraudulent requests came from an email address on a legitimate government agency domain, not a lookalike or spoofed address. Because the domain itself was genuine, the messages passed Revolut's authentication checks. Revolut has described the incident as a sophisticated external impersonation scam, indicating that the sender's apparent authority, rather than a technical flaw, was what carried the request through.

Most impersonation attempts rely on a domain that resembles a real one closely enough to survive a glance. Characters are substituted, subdomains are added, or display names are set to mimic an official title. Those attempts fail against routine checks because the underlying address does not match the organisation it claims to represent. The mechanism in this case was different. The address was on the genuine domain, which means the usual signal that a request is fraudulent was absent.

That changes the nature of the control that failed. Where a request appears to come from a real government body, the receiving organisation is weighing whether the request is properly authorised rather than whether the sender is who they claim to be. Verification then turns on process: whether the specific request was expected, whether it followed the correct internal route, and whether the person making it held the authority they asserted. Revolut has said the messages passed its authentication checks, which indicates that whatever verification was applied did not catch the discrepancy.

Revolut's description of the incident as sophisticated external impersonation places the emphasis on the external party's method. It does not address how a request from a genuine domain came to be sent, nor whether the domain itself was compromised, nor whether an authorised mailbox was misused. Those questions remain open on the facts Revolut has published, and the company has not named the agency involved, which limits what can be established about how the request originated.

What Revolut says it has done and what it has not disclosed

Revolut says it blocked the sender on detection and notified the relevant government agency, law enforcement, data protection authorities and financial regulators. It says its core systems, mobile app and customer accounts were not compromised and that customer funds remain safe. It has not published a number for affected customers and has not named the government agency whose domain was used.

The notification list is broad and covers the bodies that would ordinarily be informed. Data protection authorities, financial regulators, law enforcement and the agency whose domain was used are all named as recipients. Revolut has not said when those notifications were made, what they contained, or what response any of them has produced. The company has also not said whether the sender was identified, whether any data has been recovered or confirmed deleted, or whether the disclosed material has been observed in use.

The statement that core systems, the app and customer accounts were not compromised is a claim about the integrity of Revolut's own infrastructure. It sits alongside the acknowledgement that data left the organisation. Both can be true at once: a system can remain uncompromised while information is released through a channel that operates within it. Revolut's framing separates the two, and the separation is central to how the company has positioned the incident.

The absence of a customer number is significant for anyone trying to assess their own exposure. Revolut says it contacted affected customers directly, which means individuals who have not been contacted are, on the company's account, not among those affected. That is the only mechanism Revolut has offered for customers to determine whether they are in scope. Without a published figure, the scale of the incident cannot be independently assessed, and the characterisation of the number as limited rests on the company's statement alone.

What affected customers are being told, and what the ICO and FOS routes are

Revolut says it contacted affected customers directly. Personal data leaving an organisation under false pretences falls within UK GDPR breach rules, which require reporting to the Information Commissioner's Office where a breach is likely to result in a risk to people's rights and freedoms. Separately, the Financial Ombudsman Service handles complaints about financial firms where a customer is dissatisfied with the response received.

The ICO route concerns the handling of the breach rather than the incident itself. Organisations that process personal data are expected to report qualifying breaches to the Commissioner within 72 hours of becoming aware of them, and to inform affected individuals where there is a high risk to their rights and freedoms. The ICO publishes guidance on what counts as a personal data breach and how reporting works. A complaint to the ICO is about whether an organisation met its obligations, not a claim for compensation in itself.

The Financial Ombudsman Service route is separate and concerns the customer relationship. Where a customer has complained to a financial firm and is unhappy with the outcome, or has not received a response within the period the firm is allowed, the complaint can be escalated to the FOS. The service is free to the customer and its decisions are binding on the firm where they are accepted. The two routes address different questions and can run alongside each other.

For customers whose documents and transaction records were disclosed, the practical concern is identity theft. A passport or driving licence copy combined with a date of birth, address and full transaction history provides the raw material for applications and approaches made in someone else's name. Revolut has said it contacted affected customers directly, and that contact is the point at which any specific guidance from the company would have been provided. The company has not published what that guidance says.

What remains unconfirmed

Several elements of the incident remain unconfirmed. Revolut has not published the number of customers affected, has not named the government agency whose domain was used, and has not said how the request came to be sent from a genuine domain. It has not said whether the sender has been identified or whether any of the disclosed data has been recovered.

Blockchain investigator ZachXBT, who first surfaced the customer notice publicly, said the incident appeared to be targeted at high net worth users. That is one researcher's assessment based on the notice and is not an established finding. Revolut has not confirmed that the requests were selective in that way, and the company's own description refers to a limited number of affected customers without characterising who they are. The targeting claim should be treated as an observation rather than a confirmed detail of the incident.

Revolut holds a UK banking licence secured in recent months, which places the incident within a regulatory framework that applies to licensed banks. The company has said it notified financial regulators, though it has not specified which ones or what they have done in response. Whether any regulatory action follows, and whether the ICO opens an investigation, are matters that would be confirmed by those bodies rather than by Revolut.

The central unresolved question is how a request from a legitimate government domain came to be made by an unauthorised party. Revolut has described the incident as external impersonation and has not said more about the mechanism. Until that is established, the incident sits between two readings: a targeted deception that defeated a process, or a process that was not robust enough for the channel it was serving. Revolut's public statements support the first. The absence of detail on the second leaves it open.

What happened in the Revolut data breach?

Revolut confirmed on 12 September 2026 that it released customer information to an unauthorised third party that submitted fraudulent requests from an email address on a legitimate government agency domain. Revolut described it as a sophisticated external impersonation scam and said the messages passed its authentication checks.

What customer data was disclosed?

The disclosed data included full name, date of birth, occupation, postal address, email address and telephone number. It also included copies of identity documents such as passports or driving licences, the facial verification selfie submitted at onboarding, account statements with IBAN, account status and opening date, wallet reference numbers, withdrawal records and full transaction history including Bitcoin activity. Revolut says no biometric facial telemetry data was involved.

How many Revolut customers are affected?

Revolut has said a limited number of customers were affected and that it contacted them directly. It has not published a figure. Customers who have not been contacted are, on the company's account, not among those affected.

Were Revolut accounts or funds accessed?

Revolut says its core systems, mobile app and customer accounts were not compromised and that customer funds remain safe. The company describes the disclosure as having occurred through a request channel rather than through a breach of its systems.

Who do data breaches get reported to in the UK?

Personal data leaving an organisation under false pretences falls within UK GDPR breach rules. Organisations are expected to report qualifying breaches to the Information Commissioner's Office, and to inform affected individuals where there is a high risk to their rights and freedoms. Complaints about a financial firm's handling of a matter can be escalated to the Financial Ombudsman Service where a customer is dissatisfied with the response.

DISCLAIMER

This article is editorial information, not financial advice. Kael Tripton Ltd is not authorised or regulated by the Financial Conduct Authority. Figures were correct at the last review date shown above; verify current rates and rules with the primary sources listed below before acting.

Frequently asked questions

What happened in the Revolut data breach?

Revolut confirmed the incident on 12 September 2026 after TechCrunch reported it. An unauthorised third party submitted fraudulent requests for customer information from an email address on a legitimate government agency domain, not a lookalike address, and the messages passed Revolut's authentication checks. Revolut described it as a sophisticated external impersonation scam and said it blocked the sender on detection.

What customer data was disclosed?

The disclosed data included full name, date of birth and occupation. It also included postal address, email address and telephone number. It included copies of identity documents, passports or driving licences, and the facial verification selfie submitted at onboarding. Financial data disclosed included account statements with IBAN, account status, account opening date, wallet reference numbers, withdrawal records and full transaction history, including Bitcoin activity. No biometric facial telemetry was compromised.

How many Revolut customers are affected?

Revolut said a limited number of customers were affected and that it contacted them directly, but has not published a number. Blockchain investigator ZachXBT, who first surfaced the customer notice publicly, said the incident appeared to be targeted at high net worth users.

Were Revolut accounts or funds accessed?

Revolut said its core systems, mobile app and customer accounts were not compromised and that customer funds remain safe. The disclosed data included account statements with IBAN, account status, account opening date, wallet reference numbers, withdrawal records and full transaction history, including Bitcoin activity. Revolut said a limited number of customers were affected and it contacted them directly.

Who do data breaches get reported to in the UK?

Personal data leaving an organisation under false pretences falls within UK GDPR breach rules. In this incident, Revolut said it blocked the sender on detection and notified the relevant government agency, law enforcement, data protection authorities and financial regulators. Revolut has not named the government agency whose domain was used.

Advertisement

Kael Tripton Deals

Verified UK deals: bank switch bonuses, savings rates, insurance offers and more

Checked against provider pages and updated weekly. Every listing labelled. No commission on any financial offer.

See all offers →

Editorial Disclaimer

The content on Kaeltripton.com is for informational and educational purposes only and does not constitute financial, investment, tax, legal or regulatory advice. Kaeltripton.com is not authorised or regulated by the Financial Conduct Authority (FCA) and is not a financial adviser, mortgage broker, insurance intermediary or investment firm. Nothing on this site should be construed as a personal recommendation. Rates, figures and product details are indicative only, subject to change without notice, and should always be verified directly with the relevant provider, HMRC, the FCA register, the Bank of England, Ofgem or other appropriate authority before any financial decision is made. Past performance is not a reliable indicator of future results. If you require regulated financial advice, please consult a qualified adviser authorised by the FCA.

CT
Chandraketu Tripathi
Finance Editor · Kaeltripton.com
Chandraketu (CK) Tripathi, founder and lead editor of Kael Tripton. 22 years in finance and marketing across 23 markets. Writes on UK personal finance, tax, mortgages, insurance, energy, and investing. Sources: HMRC, FCA, Ofgem, BoE, ONS.

Stay ahead of your money

Free UK finance guides, rate changes and money-saving tips — straight to your inbox. No spam, unsubscribe anytime.

Read More

📋 In this guide
Advertisement

Get Kael Tripton in your Google feed

⭐ Add as Preferred Source on Google