Revolut data breach alert graphic warning users to check their account after passports and selfies were exposed

Revolut Data Breach: Fake Government Emails Just Exposed Passports and Selfies — Here’s What to Do

The Revolut data breach confirmed on September 12, 2026 didn’t involve any hacking of Revolut’s systems — a scammer simply asked for customer data while posing as a government agency, and Revolut handed it over. The company says money and login credentials are safe, but passports, selfies, and account statements for a “limited” number of customers are now in the wrong hands. Here’s exactly what happened, who’s affected, and what to check in your account today.

Quick facts, if you’re skimming:

  • Confirmed: September 12, 2026, in Revolut’s own statement to affected customers.
  • Cause: social engineering — an attacker used a legitimate-looking government agency email domain to request customer records.
  • Data exposed: passport and driver’s license copies, verification selfies, home addresses, phone numbers, account statements, and transaction history.
  • Data NOT exposed: Revolut says login passwords, card numbers, and customer funds were untouched.
  • Scope: a “very limited” number of accounts, though researcher ZachXBT says high-net-worth users appear to have been targeted.

How the Revolut Data Breach Actually Happened

Revolut wasn’t broken into in the way most breach stories go. In its own words, “an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” Someone sent a request from a real, trusted-looking government email address, and Revolut’s process approved it as a legitimate legal inquiry.

That’s the part that should worry every company, not just Revolut: the weak point wasn’t a firewall or an encryption key, it was a human review process trusting a familiar sender. Revolut says it caught the activity, blocked the fraudulent address, and alerted the impersonated government agency along with law enforcement, data protection authorities, and financial regulators. It hasn’t named which agency’s domain was used, which makes it hard for anyone else to know if they were targeted the same way.

What Information Got Exposed — and Who’s at Risk

The exposed data reads like a starter kit for identity theft: dates of birth, home addresses, phone numbers, copies of passports or driver’s licenses, verification selfies, and full account statements with transaction history. Put a government ID photo next to a matching selfie and you have exactly what most banks and apps use to verify a new sign-up.

That combination is also the kind of raw material that facial-matching tools are built to exploit — tools like Clearview AI’s InquiryIQ, which can stitch a single photo into a much fuller profile. Revolut insists the number of affected customers is “very limited” and hasn’t shared a figure, but on-chain investigator ZachXBT has suggested the attacker specifically went after high-net-worth users, which tracks with how targeted the request appears to have been rather than a mass scrape.

How to Spot a Scam Riding on This Breach

Whenever a breach like this hits the news, a second wave of scams usually follows, with fraudsters using the leak as cover to sound more convincing. Here’s a quick way to sanity-check anything that lands in your inbox or texts claiming to be Revolut.

What You’re Seeing What It Likely Means
A message inside the Revolut app, or a call you placed yourself using the number on the app Genuine — this is how Revolut actually reaches you.
An unexpected email or text asking you to “confirm” your PIN, one-time code, or full card number Scam — Revolut never asks for these outside the app.
A message demanding you act within hours or your account will be frozen Scam — artificial urgency is the oldest trick in the book.
A link that doesn’t clearly go to revolut.com or open your Revolut app directly Scam — don’t tap it; open the app manually instead.

This matters more than usual right now: because the attacker already has real names, addresses, and account details, a follow-up scam message can reference accurate personal information and still be fake. Treat that accuracy as a red flag, not proof that a message is legitimate.

What Revolut and Regulators Are Doing About It

Revolut says it blocked the fraudulent email address as soon as the activity was detected and directly notified every customer whose data was involved, specifying exactly what was exposed for each person. The company also looped in the impersonated government agency, law enforcement, data protection authorities, and financial regulators.

There are also unverified reports, flagged by Help Net Security, of a poster claiming to be the attacker and threatening to leak more data unless paid — Revolut hasn’t confirmed this, so treat it as an unconfirmed claim rather than settled fact for now.

What to Do If You Bank With Revolut Right Now

You don’t need to panic about your balance, but a few quick checks are worth doing today regardless of whether you’ve received a notification yet.

  • Open the Revolut app directly — don’t tap links in emails — and look for an official in-app breach notification.
  • Be extra skeptical of any message that already knows your name, address, or partial account details; that accuracy no longer proves it’s real.
  • Turn on every extra login and transaction alert Revolut offers, so unusual activity reaches you fast.
  • Since your passport or license may be exposed, consider a fraud alert or credit freeze with your national credit bureau.
  • Keep the rest of your software patched too — attackers chain small openings together, which is exactly why a fix like the recent Chrome zero-day update is worth installing the same day it lands.

None of these steps undo the exposure, but together they shrink the window an attacker has to actually use your data before you notice.

Frequently Asked Questions

Was my money stolen in the Revolut data breach?

No. Revolut says customer funds, card numbers, and login credentials were not part of this incident — the exposure was limited to identity documents and account records.

How many Revolut customers were affected?

Revolut has only described the number as “very limited” and hasn’t published an exact figure or a list of affected countries.

Did hackers get my passport photo?

Only if you’re among the customers Revolut has directly notified. If you haven’t received that notification, your documents weren’t part of this particular incident.

How do I know if I’m one of the affected customers?

Revolut says it emailed every impacted customer directly, listing exactly which of their data was exposed. Check your inbox and spam folder for that specific message before assuming either way.

Should I close my Revolut account over this?

Not necessarily. This was a social-engineering incident aimed at a support process, not a sign that Revolut’s core banking systems are unsafe — and closing the account wouldn’t undo documents that are already exposed.

My honest take: this breach is less about Revolut’s security and more about how easy it still is to talk your way past a trusted process with nothing but a convincing email address. The company’s systems held up fine; a human workflow trusting a familiar domain didn’t. If you use Revolut, don’t lose sleep over your balance, but do spend five minutes checking for that notification email and treat any oddly well-informed message you get over the next few weeks with real suspicion.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *