Revolut Data Breach Exposes Passports and Full Transaction Histories After Fake Government Request
Fintech giant Revolut has confirmed a data-security incident in which an unauthorized party obtained sensitive customer information after submitting fraudulent requests that appeared to come from a legitimate government agency.

The company said a sophisticated impersonation scam caused a limited number of customers' records to be disclosed. Revolut has not revealed the exact number of affected customers or identified the government agency involved.
Importantly, Revolut said its systems and customer funds were not compromised. The incident involved unauthorized disclosure of customer information rather than a direct breach of its core banking infrastructure.
What Data Was Exposed?
According to customer notifications reported by multiple sources, the information potentially disclosed included:
| Data Type | Potentially Exposed Information |
|---|---|
| Identity data | Names, dates of birth, occupation |
| Contact data | Home addresses, email addresses, phone numbers |
| Identity documents | Passport and driver's license copies |
| Verification data | Customer verification selfies |
| Banking information | Account statements, IBANs and account details |
| Transaction data | Withdrawal records and complete transaction histories |
| Crypto activity | Bitcoin transaction history |
The exposure of identity documents alongside financial and cryptocurrency records creates a particularly sensitive dataset that could be used for targeted phishing, impersonation and other forms of fraud.
How the Attack Worked
The incident appears to have exploited trust in a legitimate government communication channel rather than a technical vulnerability in Revolut's systems.
An unauthorized party used an email account within a legitimate government agency's domain to send fraudulent customer-information requests.
Because the messages appeared to originate from an authentic government domain, the requests passed Revolut's normal verification process and were treated as legitimate.
Revolut later contacted the government agency separately and discovered that the requests were fraudulent.
The company then blocked the unauthorized email address and notified affected customers, regulators, law enforcement and the relevant government agency.
Why the Breach Is Significant
The incident demonstrates that email authentication alone cannot establish that a request is trustworthy.
Even when messages originate from a legitimate domain, an unauthorized mailbox or compromised account inside that organization can potentially be abused to conduct convincing social-engineering attacks.
For financial institutions, requests for highly sensitive customer information should therefore require additional verification, particularly when they involve:
- Identity documents
- Full transaction histories
- Account statements
- Cryptocurrency activity
- Customer addresses and contact details
Potential Risks to Customers
Although Revolut says customer funds were unaffected, exposed information could increase the risk of:
- Targeted phishing and spear-phishing
- Identity theft
- Social engineering
- Account-recovery fraud
- Financial impersonation
- Cryptocurrency-related targeting
- Extortion attempts
The combination of passport information, verification selfies and transaction history can provide attackers with enough context to create highly convincing impersonation scenarios.
What Customers Should Do
Customers who received a breach notification should remain alert for suspicious communications claiming to be from Revolut, banks, government agencies or cryptocurrency services.
They should:
- Avoid clicking unexpected links or attachments.
- Never provide passwords, authentication codes or recovery information.
- Verify unusual requests through official Revolut channels.
- Monitor accounts and transaction activity for suspicious behavior.
- Be cautious of calls claiming to be from financial institutions or authorities.
- Report suspected fraud immediately.
Revolut said it has implemented additional security measures and notified the appropriate authorities. The company continues to investigate the incident.
The breach is a reminder that a valid government email domain does not automatically make a data request legitimate. Organizations handling sensitive financial and identity information need layered verification processes that go beyond domain authentication before releasing customer records.
SEO Meta Description:
Revolut confirms a customer data breach after fraudulent government requests exposed passports, verification selfies, IBANs and full transaction histories, including Bitcoin activity.
Related reporting
JetBrains Cadence Breached Through Unpatched TeamCity Flaw, Exposing AWS Credentials
JetBrains has disclosed a security incident in its Cadence cloud service after attackers exploited a critical, unpatched TeamCity vulnerability to gain access to the environment and compromise sensitive credentials, including AWS IAM credentials.
