Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2815+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Revolut Discloses Data Breach Exposing Financial Info, Passports
Revolut Discloses Data Breach Exposing Financial Info, Passports
NEWS

Revolut Discloses Data Breach Exposing Financial Info, Passports

A threat actor impersonating a government agency tricked Revolut into handing over passports, selfies, and full transaction histories.

Dylan H.

News Desk

September 14, 2026
3 min read

Fintech Giant Fooled by Spoofed Government Request

Revolut has disclosed a data breach affecting an undisclosed number of customers after a threat actor successfully impersonated a government agency to obtain sensitive account data. The company says the incident was contained quickly, but the scope of exposed data is severe for those affected.


How the Attacker Got In

The attacker sent an email requesting customer data that appeared to come from a legitimate government agency, using what Revolut described as the agency's official email domain. Because the message carried valid domain authentication credentials, Revolut fulfilled the request "under the reasonable belief that it was an authentic government agency request."

In other words, this wasn't a technical exploit — it was a social engineering and email-spoofing attack that slipped past domain-verification checks that would normally be trusted signals of legitimacy.


What Was Exposed

CategoryData Exposed
IdentityFull name, date of birth, occupation
ContactPostal address, email, phone number
VerificationPassport and/or driver's license copies, facial verification selfies
FinancialAccount statements, IBAN numbers, withdrawal records, full transaction histories (including Bitcoin transactions)

The combination of government ID scans, biometric selfies, and complete financial histories makes this a high-value dataset for identity theft, account takeover, and targeted fraud.


Scale and Targeting

Revolut declined to disclose exact victim numbers, describing the impact as affecting a "very limited" number of customers. However, crypto fraud investigator ZachXBT suggested the breach "seems to have been targeted at high net worth users" — raising the stakes for those individuals well beyond a typical mass-breach scenario.


Revolut's Response

Revolut stated that core systems and customer funds were unaffected:

"Revolut systems and customer funds are unaffected. Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators."


Not Revolut's First Breach

This marks Revolut's second disclosed breach. In 2022, attackers accessed the personal data of 50,150 customers through a separate incident. The recurrence underscores that fintechs handling large volumes of sensitive identity and financial data remain high-value, repeat targets — and that process-level failures (trusting a spoofed but domain-authenticated request) can be just as damaging as technical vulnerabilities.


Protective Steps for Affected Users

  1. Assume ID documents are compromised — monitor for identity-theft attempts using your passport or driver's license number.
  2. Watch for targeted phishing referencing your real transaction history or account details.
  3. Enable additional account monitoring and transaction alerts within the Revolut app.
  4. Be skeptical of unsolicited contact claiming to be from Revolut, government agencies, or law enforcement following this breach.

Related Reading

  • Zara Data Breach Exposed Personal Information of 197,000 People
  • Vimeo Confirms Anodot Breach Exposed User Data
#Data Breach#Revolut#Fintech#Social Engineering#Financial Services

Related Articles

Apollo Discloses Data Breach from Ongoing Wave of Attacks Hitting Financial Sector

Apollo Global Management confirms a July 2026 breach via IT helpdesk social engineering, exposing PII including SSNs in a coordinated wave targeting PE firms.

5 min read

Fintech Giant Figure Technology Confirms Breach: Nearly 1

Blockchain-based lending platform Figure Technology Solutions confirms a data breach affecting nearly 1 million customers after ShinyHunters exploited an...

5 min read

Marquis Ransomware Breach: 672K People Exposed as Attack

Texas fintech Marquis Software Solutions has confirmed a ransomware attack in August 2025 exposed data of 672,000+ individuals and disrupted operations at...

6 min read
Back to all News