Published September 15, 2026 - New York. Revolut has disclosed a data breach in which sensitive customer records, including passport copies, KYC verification selfies and full transaction histories, were handed to a threat actor after a fraudulent request that appeared to come from a legitimate government agency, with self-proclaimed culprits now demanding a 10,000 bitcoin ransom.
At a glance
- An unauthorized sender used a real government agency email domain to request customer data, and the messages carried valid domain authentication credentials, so Revolut fulfilled them.
- The exposed data set includes names, dates of birth, occupations, addresses, phone numbers, passport or driver license copies, KYC selfies, IBANs, withdrawal records and full transaction histories, including Bitcoin activity.
- Revolut says a very limited number of customers were affected, that core systems and customer funds are untouched, and that it has not released an exact count.
- Self-described culprits posted snippets of high-profile individuals in Telegram groups and threatened to release more data every day until Revolut pays 10,000 bitcoin, an amount worth over 780 million dollars.
- Anyone who received a notice should assume their complete identity profile is in criminal hands and prepare for targeted phishing, impersonation and crypto scams.
Data last verified September 15, 2026 from BleepingComputer, TechCrunch, Reuters and The Register.
Quick Answer
Revolut was not breached through its infrastructure - it was socially engineered into handing data over. A threat actor submitted fraudulent information requests from an unauthorized email account operating on a genuine government agency domain, and because the communication passed domain authentication checks, Revolut disclosed the requested customer information in the reasonable belief that it was responding to a legitimate agency. The company has blocked the sender, alerted the relevant government agency, law enforcement, data protection and financial regulators, and says customer funds and systems are unaffected. If you were notified, your KYC file and financial history should be treated as exposed.
What happened at Revolut
News of the incident broke on September 12, 2026, when Revolut confirmed to Reuters and TechCrunch that sensitive customer information had been disclosed to an unauthorized third party after the company received fraudulent requests sent from a legitimate government agency email domain. In notifications to affected customers, the fintech described a sophisticated external impersonation scam: the request came from an unauthorized email account but was sent directly using the official government agency domain, and because the communication carried valid domain authentication credentials, it was fulfilled in the reasonable belief it was authentic.
The scale of what was shared is unusual. According to the breach notifications, the data includes identity details such as full names, dates of birth and occupations; contact details including postal addresses, email addresses and telephone numbers; document and verification data such as copies of passports or driver licenses and facial verification selfies collected for Know Your Customer checks; and financial records including account statements with IBAN numbers, withdrawal records and full transaction histories, including Bitcoin transactions.
The aftermath has turned into a public extortion attempt. As reported by The Register on September 14, self-proclaimed culprits have been posting in multiple Telegram groups, sharing snippets of data belonging to high-profile individuals - including chief executives, sports professionals and performing artists - and threatening to release more and more data every day until Revolut pays. Their demand: 10,000 bitcoin, which at mid-September prices is worth more than 780 million dollars. Blockchain investigator ZachXBT circulated the customer notifications, and reporting around his posts claims the attackers deliberately targeted high-net-worth users.
Who is affected
Revolut has told reporters the breach affects a very limited number of customers, but it has repeatedly declined to give an exact figure, which makes independent verification impossible. What is clear is the profile of the data: people whose full KYC bundles - government ID, selfie, address and complete financial trail including crypto activity - were handed over in one package. That combination is a premium product for fraudsters, enabling account takeover attempts, convincing impersonation scams, identity theft and highly targeted cryptocurrency fraud.
The timing is sensitive for the company. Revolut serves more than 80 million personal customers and around 800,000 business customers across over 160 countries and regions, operates as a bank in more than 30 countries, and is widely reported to be preparing for a potential public listing at a valuation that could reach 200 billion dollars. A breach involving government-domain impersonation inevitably raises questions about how fintechs verify legal data requests before releasing customer files.
How to check if you are affected
Revolut says it has contacted affected customers directly by email, so the definitive signal is a notice from Revolut itself. Check the inbox linked to your Revolut account, including spam folders, for a message describing the incident. Be extremely skeptical of any follow-up phone calls, texts or emails referencing the breach - attackers already have your contact details, and impersonating Revolut support is the obvious next move for criminal groups.
Even customers who did not receive a notice should stay alert over the coming weeks. Watch for unexpected identity verification prompts, password reset emails you did not request, and approaches that reference your transaction history or crypto holdings, since reporting indicates the attackers focused on high-value accounts.
What to do next
If you received a notification, treat your identity documents and financial footprint as compromised and take these steps now:
- Contact Revolut through the in-app support channel only, never through links in emails or texts.
- Change your Revolut passcode and the password of the email account tied to it, and make sure each is unique.
- Enable or verify app-based security controls such as biometric locks, transaction signing and disposable virtual cards.
- Scrutinize any government, bank or exchange communication that references your accounts; assume attackers can quote your real data back at you.
- Warn family members and business associates if your shared accounts or contact lists could be used against them.
- Consider placing a fraud alert or credit freeze with credit bureaus where available, since passport and ID copies were exposed.
Beyond individual actions, this incident is a warning about data-request verification. Domain authentication proves a message came from a domain - not that the sender is authorized to ask for anything. Companies that hold KYC data need out-of-band verification for government requests, and customers should understand that the most sensitive documents they ever uploaded are only as safe as the weakest process at the company holding them.






