What we know about the Revolut data breach so far
Revolut confirmed an impersonation scheme exposed high-net-worth customers' identity documents, IBANs, and transaction histories to an attacker.
Revolut confirmed on September 12 that someone impersonating a government agency, using an email address on that agency's domain, obtained sensitive customer records. Exposed data includes birth dates, postal and email addresses, phone numbers, passport and driving licence copies, verification selfies, account statements, and transaction histories; ZachXBT added that IBANs, withdrawal records, occupations, and bitcoin transaction history were also included. Revolut says a limited number of customers were affected, the sender's address was blocked, and its systems and customer funds were untouched, with law enforcement and regulators notified.
- Attacker impersonated a government agency via email to obtain customer KYC records
- Data includes passports, driving licences, selfies, IBANs, and transaction histories
- ZachXBT assesses limited scale but targeting of high-net-worth users
- Revolut blocked the sender and alerted law enforcement, regulators, and the agency
Full article174 words · extracted from helpnetsecurity.com · click to collapse
Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the incident on Saturday, September 12.

The London-based fintech told TechCrunch that a limited number of customers were affected and that it had contacted them directly.
The notification Revolut emailed affected customers listed birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences. Verification selfies, account statements and transaction histories may also have gone out, the bank said.
ZachXBT, the crypto investigator who publicized the notice in a Telegram post, added several items Revolut left out: IBANs, withdrawal records, occupations, and transaction history covering bitcoin. He judged the incident limited in scale but aimed at high-net-worth users.
Revolut said it blocked the sender’s address on detecting the scheme and alerted the government agency concerned, law enforcement, data protection authorities and financial regulators. A spokesperson characterized the episode as an external impersonation scam and said the company’s systems and customer funds were untouched.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/14/revolut-data-breach-privacy/