Revolut Customers' Passports, Selfies and Transaction Data Exposed After Fake Government Request
Revolut confirmed sensitive customer data was disclosed after an attacker impersonated a government agency

Revolut has confirmed that sensitive customer information was disclosed after an unauthorised third party used a legitimate government agency email domain to submit fraudulent requests for data.
The London-based fintech said a limited number of customers were affected. A notification sent to those customers said the information potentially disclosed included passports and driving licences, verification selfies, dates of birth, postal and email addresses, phone numbers, account statements and transaction histories.
Revolut said its systems and customer funds were not affected. It blocked the email address after detecting the scam and alerted the relevant government agency, law enforcement, data-protection authorities and financial regulators.
What Customer Data Was Exposed
The company has not disclosed the agency involved, the exact number of affected customers or the period during which information was exposed. It said it had contacted affected customers directly.
The customer notification, reviewed by TechCrunch, said the exposed information may have included identity documents and contact details, as well as verification selfies. Account statements and transaction histories, including Bitcoin transactions, may also have been disclosed.
The incident did not involve an intrusion into Revolut's core banking systems. Instead, an unauthorised third party used an email address on a legitimate government agency domain to make fraudulent information requests.
How Fake Government Requests Bypassed Checks
Revolut described the activity as a 'sophisticated external impersonation scam'. Rather than penetrating its technical infrastructure, the third party used a legitimate government email domain to make its requests appear authentic.
Security researcher ZachXBT said the incident appeared to have targeted high-net-worth users. Revolut has not publicly confirmed that assessment.
The incident follows separate data exposures involving other major UK businesses. In September 2025, HSBC warned business banking customers that identity documents, images and contact information had been compromised through unauthorised access to a third-party platform. Harrods also reported that names and contact information had been taken from a third-party provider, while saying payment details and passwords were not exposed.
For affected Revolut customers, the combination of identity documents and financial information could increase the risk of targeted phishing, identity theft and attempts to impersonate bank staff or other trusted organisations.
What Revolut Customers Need to Know
Revolut has not identified the government agency involved or provided a public figure for the number of affected customers. The company said it had contacted those individuals directly.
The breach comes as Revolut continues to expand internationally. The company says it has more than 80 million customers globally and recently received conditional approval from the US Office of the Comptroller of the Currency to establish a national bank.
Under Information Commissioner's Office guidance, organisations must report a personal data breach without undue delay and, where feasible, within 72 hours if it is likely to pose a risk to people's rights and freedoms. Where the risk is high, affected individuals must also be informed without undue delay.
Revolut has advised affected customers to remain alert to suspicious communications and verify requests through official channels. The company has not disclosed the full scope of the incident or identified the government agency whose email domain was used.
© Copyright IBTimes 2026. All rights reserved.
























