Revolut Data Breach Via Fake Government Requests – What We Know So Far
Revolut confirmed attackers extracted customer KYC records by sending fraudulent data requests from a spoofed or compromised government agency email domain.
Revolut confirmed a data breach in which an unauthorized party obtained sensitive customer records by submitting fraudulent information requests from an email account on a legitimate government agency domain with valid SPF/DKIM/DMARC authentication. Disclosed data could include full names, dates of birth, passport or driving-license copies, onboarding facial images, IBANs, account statements, withdrawal records, and complete transaction histories including Bitcoin activity. Crypto investigator ZachXBT assessed the operation targeted high-net-worth users, while a threat actor using the name 'IAmNotAVillain' claimed Italian law-enforcement departments were compromised over six months with 147 GB of material, claims that remain unverified. Revolut says only a limited number of customers were affected, blocked the email address, and notified regulators and affected customers, stating its systems and funds were not compromised.
Revolut discloses data breach exposing financial info, passports
Revolut disclosed a breach after a threat actor spoofing a government agency's email domain obtained customer passports, selfies, IBANs, and full transaction histories.
Revolut told affected customers that a threat actor sent a data request from an unauthorized email account on an official government agency's domain, carrying valid domain authentication credentials, and staff fulfilled it believing it legitimate. Exposed data includes identity details, contact information, passport and driver's license copies, KYC facial verification selfies, IBANs, withdrawal records, and full transaction histories including Bitcoin. Revolut calls the number of affected customers 'very limited' but refuses to give exact figures, while ZachXBT says high-net-worth users appear targeted. This follows a 2022 Revolut breach affecting 50,150 customers.
What we know about the Revolut data breach so far
Revolut confirmed an impersonation scheme exposed high-net-worth customers' identity documents, IBANs, and transaction histories to an attacker.
Revolut confirmed on September 12 that someone impersonating a government agency, using an email address on that agency's domain, obtained sensitive customer records. Exposed data includes birth dates, postal and email addresses, phone numbers, passport and driving licence copies, verification selfies, account statements, and transaction histories; ZachXBT added that IBANs, withdrawal records, occupations, and bitcoin transaction history were also included. Revolut says a limited number of customers were affected, the sender's address was blocked, and its systems and customer funds were untouched, with law enforcement and regulators notified.
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
Weekly roundup: Microsoft patches 973 flaws including two actively exploited zero-days; FortiOS CAPWAP flaw deploys PivotC2 RAT; PAN-OS root RCE disclosed.
Microsoft's September 2026 Patch Tuesday fixed 973 vulnerabilities, including two zero-days under active exploitation: CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack), both elevation-of-privilege bugs. SOCRadar reported active exploitation of CVE-2025-25249 (CVSS 9.8) in FortiOS CAPWAP, deploying a Node.js RAT called PivotC2 that exfiltrates Exchange mailboxes to Wasabi cloud storage; 178 devices were compromised out of 30,000 scanned IPs, attributed to a Russian-speaking financially motivated group. Palo Alto disclosed CVE-2026-0310, a 9.2-rated buffer overflow enabling root code execution on PA-Series firewalls, and Fortinet disclosed CVE-2026-84393, a ZTNA certificate validation MITM flaw. Cyera also revealed CVE-2026-6471 ('PostGREShell'), a 12-year-old PostgreSQL logical-decoding flaw allowing code execution via REPLICATION-privileged accounts.
Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers
Revolut leaked KYC documents and full transaction histories after a fraudulent, domain-authenticated email request impersonating a government agency.
Revolut disclosed that an attacker using an unauthorized email account on a legitimate government domain, with valid domain-authentication credentials, tricked the fintech into releasing customer data. The exposed data includes passport and driver's license copies, identity-verification selfies, full names, dates of birth, addresses, IBANs, and complete transaction histories including Bitcoin activity. Revolut says core systems, accounts, and funds were not compromised, and it blocked the email source and notified authorities. On-chain investigator ZachXBT and others indicated the operation targeted high-net-worth users facing elevated phishing, SIM-swap, and extortion risk.
Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks
Revolut handed over KYC documents, selfies, and Bitcoin transaction histories to attackers after a fraudulent email from a genuine government domain passed authentication checks.
Revolut confirmed on September 12, 2026 that it disclosed sensitive customer KYC data to an unauthorized third party after a fraudulent information request was sent from an email account operating inside a real government agency's domain, carrying valid domain authentication credentials. The exposed data included identity documents (passports, driver's licenses), verification selfies, birth dates, contact details, IBANs, account statements, and full transaction histories including Bitcoin. Revolut discovered the fraud only after independently verifying with the agency, blocked the sender, and notified law enforcement and financial regulators, but did not disclose the number of affected customers or the agency involved. Researcher ZachXBT assessed the operation was targeted at high-net-worth users, useful for fraud, impersonation, or extortion.
Revolut confirms customer data breach through fake government requests
Revolut disclosed customer identity data, including passports and possibly selfies, to an attacker using a legitimate government email domain.
Attackers impersonating a government agency used a legitimate agency email domain to submit fraudulent information requests, prompting Revolut to disclose customer identity and contact data to an unauthorized third party. Exposed data included birth dates, postal and email addresses, phone numbers, passport and driver's license copies, and possibly verification selfies, account statements, and transaction histories. Revolut said a limited number of customers were affected, blocked the email address, and notified the agency, law enforcement, and regulators, adding that systems and customer funds were unaffected. Security researcher ZachXBT reported the scam appeared to target high net worth users of the fintech, which serves over 80 million customers.
Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft
Malone Lam's plea hearing approaches in the $240 million bitcoin social engineering theft; the case highlights surging crypto fraud and limited enforcement.
Malone Lam, accused of organizing a social engineering attack that stole over $240 million in bitcoin (4,100+ BTC) from a Washington, D.C. resident in August 2024, has a plea agreement hearing set. Callers impersonating Google and Gemini staff tricked the victim into revealing security codes. Lam and 17 co-defendants spent lavishly before FBI arrests; crypto investment fraud complaints to the FBI rose nearly 50% in 2025 while DOJ disbanded its crypto crimes unit.