Revolut Breach Exposes Passports, IBANs, Bitcoin Data; 80M Users at Risk
Revolut confirms an attacker used a legitimate government-agency domain email with valid authentication to trick staff into releasing KYC/AML data and full financial histories. The exposed records include passport scans, verification selfies, IBANs, and Bitcoin transaction histories. Security teams should treat legal-request channels as a high-value social engineering surface.
Beat this week
Last 7 days · Data Breaches
Impact 6.5/10 (-0.2 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.
This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- Revolut confirms an attacker used a legitimate government-agency domain email with valid authentication to trick staff into releasing KYC/AML data and full financial histories.
- The exposed records include passport scans, verification selfies, IBANs, and Bitcoin transaction histories.
- Security teams should treat legal-request channels as a high-value social engineering surface.
- SecurityWeek
- BleepingComputer
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Revolut serves more than 80 million users in over 160 countries and 800,000 business customers.
- 2Attackers used a legitimate government agency domain email with valid authentication credentials to request PII.
- 3Exposed data included names, addresses, dates of birth, occupation, passport and driver's license copies, verification selfies, IBANs, account statements, withdrawal records, and full transaction history including Bitcoin.
- 4Revolut immediately blocked the attacker's email and notified the relevant government agency, enforcement agencies, data protection, and financial regulators.
- 5Revolut stated systems and customer funds were unaffected but did not disclose the number of impacted customers.
- 6SecurityWeek and BleepingComputer reported the breach on September 14, 2026, and crypto fraud investigator ZachXBT commented over the weekend.
Who's Affected
Analysis
A threat actor didn't breach Revolut's core banking systems—it exploited the trust mechanism that financial institutions must maintain for government legal requests. The 80 million-user neobank handed over passports, selfies, IBANs, and full Bitcoin transaction histories because an inbound email carried valid domain credentials. For cybersecurity teams, this is a warning that domain authentication alone cannot secure high-sensitivity PII flows.
On September 11, 2026, British fintech giant Revolut began notifying a subset of its more than 80 million customers across 160 countries that a third party posing as a government agency had obtained extensive personal and financial information through email requests that carried valid technical domain credentials. The London-based neobank, which also serves 800,000 business customers, confirmed the incident to SecurityWeek and BleepingComputer, stating that the exposed records included full names, postal addresses, phone numbers, email addresses, dates of birth, occupation, copies of driver's licenses and passports, facial verification selfies used for Know Your Customer checks, IBANs, account statements, withdrawal records, and complete transaction histories, including Bitcoin activity. Revolut emphasized that its systems and customer funds were unaffected and that only a limited number of individuals were impacted, but it declined to disclose an exact figure.
A threat actor didn't breach Revolut's core banking systems—it exploited the trust mechanism that financial institutions must maintain for government legal requests.
The attack illustrates a dangerous evolution in business email compromise and social engineering. Rather than breaching Revolut's internal systems or exploiting a software vulnerability, the threat actor leveraged a legitimate government agency domain email with valid authentication credentials to submit fraudulent requests for information. Financial institutions are legally required to comply with lawful requests from government and law enforcement agencies, so the email's domain authentication provided enough confidence for Revolut to fulfill it. A Revolut spokesperson characterized the event as a 'sophisticated external impersonation scam' and said the company immediately blocked the attacker's email address upon detection, then alerted the relevant government agency, enforcement agencies, data protection authorities, and financial regulators.
For affected users and the broader fintech sector, the exposure is unusually severe. The combination of government-grade identity documents, facial selfies, and comprehensive financial histories, including Bitcoin transactions, creates a rich data set for identity theft, account takeover, targeted phishing, extortion, and even cryptocurrency-related fraud. Unlike a payment card number that can be replaced, passports, driver's licenses, and biometric selfies cannot be easily reissued. Full transaction histories can reveal spending patterns, employer details, and crypto holdings, enabling highly convincing impersonation. The fact that Revolut has not revealed how many customers were affected compounds uncertainty; the absence of a disclosed figure makes it difficult for regulators, banks, and individuals to assess scope and respond appropriately.
What to Watch
The regulatory and legal implications are significant. Revolut's notification to data protection and financial regulators means the incident will likely be reviewed under the UK General Data Protection Regulation and possibly by the Information Commissioner's Office, as well as other European and global authorities. The exposure of passports and selfies may trigger mandatory breach notifications in multiple jurisdictions, and the involvement of Bitcoin transaction history adds anti-money-laundering and financial crime angles. For security teams, the core lesson is that domain authentication alone is not sufficient for high-sensitivity legal requests. Organizations must implement out-of-band verification, such as callback procedures to known government contacts, cryptographic verification of legal process, request metadata validation, and strict data minimization so that only the minimum necessary KYC and financial information is disclosed.
Looking forward, Revolut will face pressure to explain how its legal-response workflow allowed a fraudulent government-domain email to succeed, and whether the domain belonged to a compromised or otherwise abused government account. Crypto fraud investigator ZachXBT's weekend commentary signals that the incident has already drawn attention from the cryptocurrency community, which is especially sensitive to transaction history exposure. The case may accelerate industry adoption of zero-trust principles for inbound legal requests, stronger email authentication standards such as DMARC and BIMI combined with human verification, and more granular access controls around KYC document stores. More fundamentally, it raises a strategic question for fintechs: retaining full passports, selfies, and complete transaction histories may be legally required for compliance but also creates a catastrophic single point of failure. Expect privacy regulators to scrutinize data retention periods and request-handling policies in the months ahead, making this incident a likely benchmark for how neobanks balance compliance obligations against breach resilience.
Timeline
Timeline
Revolut notifies affected users
Revolut emails a subset of customers that PII and financial data were exposed to a third party posing as a government agency.
Public disclosure via security media
SecurityWeek and BleepingComputer publish reports; Revolut confirms details, says systems and funds unaffected, and blocked attacker address.
Source cluster
Primary reporting
- BleepingComputerRevolut discloses data breach exposing financial info, passports
Cite This Page
"Revolut Breach Exposes Passports, IBANs, Bitcoin Data; 80M Users at Risk." Cyber Intelligence Brief, September 14, 2026. https://getcyberbrief.com/story/revolut-data-breach-government-domain-impersonation-cyber
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |