Data Breaches Negative 7

Revolut Breach Exposes Passports, IBANs, Bitcoin Data; 80M Users at Risk

Revolut confirms an attacker used a legitimate government-agency domain email with valid authentication to trick staff into releasing KYC/AML data and full financial histories. The exposed records include passport scans, verification selfies, IBANs, and Bitcoin transaction histories. Security teams should treat legal-request channels as a high-value social engineering surface.

· 4 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Data Breaches

2 stories
6.5 avg impact
0% positive
100% negative
vs prior 7 days -1 -1 story vs prior 7 days

Impact 6.5/10 (-0.2 vs prior). Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.

  • 100% negative

This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

7 impact
Negativesentiment
2sources
4min read
  1. Revolut confirms an attacker used a legitimate government-agency domain email with valid authentication to trick staff into releasing KYC/AML data and full financial histories.
  2. The exposed records include passport scans, verification selfies, IBANs, and Bitcoin transaction histories.
  3. Security teams should treat legal-request channels as a high-value social engineering surface.
Drawn from
  • SecurityWeek
  • BleepingComputer

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Revolut serves more than 80 million users in over 160 countries and 800,000 business customers.
  2. 2Attackers used a legitimate government agency domain email with valid authentication credentials to request PII.
  3. 3Exposed data included names, addresses, dates of birth, occupation, passport and driver's license copies, verification selfies, IBANs, account statements, withdrawal records, and full transaction history including Bitcoin.
  4. 4Revolut immediately blocked the attacker's email and notified the relevant government agency, enforcement agencies, data protection, and financial regulators.
  5. 5Revolut stated systems and customer funds were unaffected but did not disclose the number of impacted customers.
  6. 6SecurityWeek and BleepingComputer reported the breach on September 14, 2026, and crypto fraud investigator ZachXBT commented over the weekend.

Who's Affected

Revolut
companyNegative
Affected Revolut customers
user_groupNegative
Threat actor
threat_actorPositive
Regulators
regulatorNeutral

Analysis

A threat actor didn't breach Revolut's core banking systems—it exploited the trust mechanism that financial institutions must maintain for government legal requests. The 80 million-user neobank handed over passports, selfies, IBANs, and full Bitcoin transaction histories because an inbound email carried valid domain credentials. For cybersecurity teams, this is a warning that domain authentication alone cannot secure high-sensitivity PII flows.

On September 11, 2026, British fintech giant Revolut began notifying a subset of its more than 80 million customers across 160 countries that a third party posing as a government agency had obtained extensive personal and financial information through email requests that carried valid technical domain credentials. The London-based neobank, which also serves 800,000 business customers, confirmed the incident to SecurityWeek and BleepingComputer, stating that the exposed records included full names, postal addresses, phone numbers, email addresses, dates of birth, occupation, copies of driver's licenses and passports, facial verification selfies used for Know Your Customer checks, IBANs, account statements, withdrawal records, and complete transaction histories, including Bitcoin activity. Revolut emphasized that its systems and customer funds were unaffected and that only a limited number of individuals were impacted, but it declined to disclose an exact figure.

A threat actor didn't breach Revolut's core banking systems—it exploited the trust mechanism that financial institutions must maintain for government legal requests.

The attack illustrates a dangerous evolution in business email compromise and social engineering. Rather than breaching Revolut's internal systems or exploiting a software vulnerability, the threat actor leveraged a legitimate government agency domain email with valid authentication credentials to submit fraudulent requests for information. Financial institutions are legally required to comply with lawful requests from government and law enforcement agencies, so the email's domain authentication provided enough confidence for Revolut to fulfill it. A Revolut spokesperson characterized the event as a 'sophisticated external impersonation scam' and said the company immediately blocked the attacker's email address upon detection, then alerted the relevant government agency, enforcement agencies, data protection authorities, and financial regulators.

For affected users and the broader fintech sector, the exposure is unusually severe. The combination of government-grade identity documents, facial selfies, and comprehensive financial histories, including Bitcoin transactions, creates a rich data set for identity theft, account takeover, targeted phishing, extortion, and even cryptocurrency-related fraud. Unlike a payment card number that can be replaced, passports, driver's licenses, and biometric selfies cannot be easily reissued. Full transaction histories can reveal spending patterns, employer details, and crypto holdings, enabling highly convincing impersonation. The fact that Revolut has not revealed how many customers were affected compounds uncertainty; the absence of a disclosed figure makes it difficult for regulators, banks, and individuals to assess scope and respond appropriately.

What to Watch

The regulatory and legal implications are significant. Revolut's notification to data protection and financial regulators means the incident will likely be reviewed under the UK General Data Protection Regulation and possibly by the Information Commissioner's Office, as well as other European and global authorities. The exposure of passports and selfies may trigger mandatory breach notifications in multiple jurisdictions, and the involvement of Bitcoin transaction history adds anti-money-laundering and financial crime angles. For security teams, the core lesson is that domain authentication alone is not sufficient for high-sensitivity legal requests. Organizations must implement out-of-band verification, such as callback procedures to known government contacts, cryptographic verification of legal process, request metadata validation, and strict data minimization so that only the minimum necessary KYC and financial information is disclosed.

Looking forward, Revolut will face pressure to explain how its legal-response workflow allowed a fraudulent government-domain email to succeed, and whether the domain belonged to a compromised or otherwise abused government account. Crypto fraud investigator ZachXBT's weekend commentary signals that the incident has already drawn attention from the cryptocurrency community, which is especially sensitive to transaction history exposure. The case may accelerate industry adoption of zero-trust principles for inbound legal requests, stronger email authentication standards such as DMARC and BIMI combined with human verification, and more granular access controls around KYC document stores. More fundamentally, it raises a strategic question for fintechs: retaining full passports, selfies, and complete transaction histories may be legally required for compliance but also creates a catastrophic single point of failure. Expect privacy regulators to scrutinize data retention periods and request-handling policies in the months ahead, making this incident a likely benchmark for how neobanks balance compliance obligations against breach resilience.

Timeline

Timeline

  1. Revolut notifies affected users

  2. Public disclosure via security media

Source cluster

Primary reporting

2articles

Cite This Page

"Revolut Breach Exposes Passports, IBANs, Bitcoin Data; 80M Users at Risk." Cyber Intelligence Brief, September 14, 2026. https://getcyberbrief.com/story/revolut-data-breach-government-domain-impersonation-cyber

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.