Quick Answer
Revolut disclosed customer records after fraudsters used an email account on a legitimate government domain to submit fake legal requests. The company says customer accounts, systems, and funds were unaffected, but exposed material may include passports, selfies, contact details, and transaction records. Check Revolut communications, watch for targeted phishing, and place fraud alerts if identity documents were involved.
Key Takeaways
- Revolut says criminals impersonated a government agency through a real government-domain email account.
- Potentially exposed records include identity documents, verification selfies, contact details, and financial activity.
- Revolut says its systems, customer accounts, and customer funds were not compromised.
- Identity documents and transaction records can make phishing and identity fraud more convincing.
- Affected customers should review Revolut notices, monitor financial accounts, and consider a fraud alert.
What happened in the Revolut data breach?
The Revolut data breach involved fraudulent information requests that appeared to come from a legitimate government email domain. Revolut said an unauthorized party used the email account to submit requests that staff processed through the company’s normal legal-compliance process, rather than by breaking into customer accounts or Revolut’s internal systems. Revolut’s spokesperson described the attack method as a sophisticated external impersonation scam.
The incident became public on September 12, 2026, and Revolut provided additional confirmation on September 14, 2026. The company said the fraudulent sender used a real government-domain address, which gave the requests credibility during the review process. This matters because legal and regulatory request workflows often depend on verified-looking official communications, and an attacker who controls or abuses such an address can exploit trust outside a company’s technical defenses.
Revolut said the affected group was “very limited,” but the company did not disclose the number of customers involved or identify the government agency whose domain was abused. The limited scope is important, but it does not remove the risk for people whose records were included. Customers should treat any direct communication from Revolut about the incident as important and verify the message through the Revolut app or official support channels before responding.
What customer data may have been exposed?
Revolut says the potentially disclosed records included names, dates of birth, postal addresses, email addresses, phone numbers, and copies of passports or driver’s licenses. The company’s customer notice also said verification selfies, account statements, IBANs, withdrawal records, and complete transaction histories may have been exposed, including Bitcoin activity. Revolut’s reported customer notice sets out the categories of information that may be involved.
Identity verification records create a more serious privacy concern than a basic email-address leak because they can give criminals enough personal context to build convincing scams. A passport or driver’s license can reveal a full legal name, date of birth, document number, and physical address. A verification selfie can also make a fraudulent support request or social-engineering attempt appear more credible, even though the disclosed information does not automatically allow an attacker to take over an account.
| Potentially exposed data | Why it matters | Practical response |
|---|---|---|
| Name, date of birth, address, email, phone number | Criminals can personalize phishing, impersonation, and account-recovery attempts. | Verify unexpected messages through official apps or websites. |
| Passport or driver’s license copies | Identity documents can increase the risk of identity-fraud attempts. | Consider a fraud alert and monitor credit reports. |
| Verification selfies | Selfies may add credibility to identity impersonation attempts. | Do not send new identity images after an unsolicited request. |
| IBANs, statements, withdrawals, transaction history | Financial activity can support targeted scams and privacy intrusion. | Review account activity and confirm payment instructions independently. |
| Bitcoin activity | Transaction history can reveal financial behavior and increase targeting risk. | Be skeptical of crypto recovery, tax, and investment messages. |
Were Revolut accounts and customer funds breached?
Revolut says customer accounts, customer funds, and Revolut’s systems were unaffected by the incident. The company described the event as an improper disclosure through a manipulated information-request process, not a breach in which attackers entered customer accounts. That distinction means customers do not have evidence from Revolut’s statement that passwords, login credentials, or balances were directly accessed through this event.
Revolut account security still deserves attention because exposed identity and transaction data can support later attacks. A criminal who knows a customer’s name, address, recent transfers, or Bitcoin activity may send a message that appears to come from Revolut, a bank, a tax authority, or a cryptocurrency service. The practical risk is targeted deception, not a confirmed immediate loss of funds.
Revolut said it blocked the fraudulent email address, contacted affected customers, and notified the relevant government agency, law enforcement, regulators, and data-protection authorities. Independent coverage also described the incident as a disclosure caused by fake government requests rather than a compromise of Revolut’s customer systems. The public disclosure details reinforce that distinction.
Why does the Revolut data breach create a phishing risk?
The Revolut data breach can make phishing attempts more persuasive because the exposed information may include details that a stranger would not normally know. A message that includes your full name, address, account activity, or identity-document details can appear more legitimate than a generic scam. Criminals often use that context to pressure people into revealing one-time passcodes, approving payments, or sending new identity documents.
Revolut customers should be especially cautious of messages claiming that a document needs to be reverified, a payment has been frozen, a crypto transaction requires confirmation, or a government agency needs more information. Do not use a link or phone number in an unexpected email, text, or social media message. Open the Revolut app directly, use the company’s official website, or independently locate a verified support channel.
Phishing campaigns can also imitate unrelated financial brands once criminals have identity information. The same pattern appeared in a separate incident where attackers used breach-related messages to target wallet users through fraudulent communications. Customers who understand how breach phishing works are less likely to treat a personalized message as proof that the sender is legitimate.
What should affected Revolut customers do now?
Revolut customers should first check whether Revolut sent a direct incident notice through the app, an established account email address, or another verified company channel. Do not reply to an unexpected message asking for a password, one-time code, recovery phrase, card number, or new identity document. Revolut’s disclosure does not establish that every customer was affected, so customers should avoid assuming a generic phishing message confirms inclusion in the incident.
- Open the Revolut app directly and review notifications, account activity, and contact details.
- Change the Revolut password if you reused it on another service or believe someone may know it.
- Enable the strongest available account security options, including app-based verification where offered.
- Review linked bank accounts, cards, transfers, and cryptocurrency activity for transactions you do not recognize.
- Contact Revolut through an official support route if a notice identifies you as affected or account activity appears unusual.
Financial-account monitoring is most useful when it focuses on real signals, such as unfamiliar transfers, changed contact details, new devices, or account-recovery messages you did not request. Customers should also avoid posting screenshots of account statements or transaction histories on social media, because exposed information can become more useful to scammers when combined with public details.
Should Revolut customers place a fraud alert or credit freeze?
Revolut customers whose passport or driver’s license information was exposed should consider placing a fraud alert with a US credit bureau, particularly if the company’s notice confirms that identity documents were involved. A fraud alert tells creditors to take extra steps to verify identity before opening new credit, while a credit freeze restricts access to a credit report for new-account applications. The appropriate choice depends on the customer’s risk tolerance and whether there are signs of identity misuse.
A credit freeze provides stronger protection against many new-credit fraud attempts, but it can also require planning when you legitimately apply for credit. A fraud alert is less restrictive and may be suitable for customers who want an added verification step without managing a freeze. Customers should review their credit reports and consider contacting a credit bureau directly rather than relying on links in breach-related emails.
Identity-document exposure does not guarantee identity theft, but it creates a reason to monitor for it over time. Customers should stop and contact a bank, credit bureau, or identity-theft professional if they find an unfamiliar credit inquiry, account, loan, tax filing, or address change. Financial losses or suspected identity theft should also be documented promptly with the affected institution and appropriate authorities.
How can Revolut customers protect Bitcoin and transaction privacy?
Revolut customers with Bitcoin activity in the potentially disclosed records should expect more targeted cryptocurrency scams. Transaction histories can reveal that someone has used Bitcoin, and criminals frequently exploit that knowledge through fake tax notices, wallet-security warnings, investment offers, and fraudulent recovery services. Exposed transaction information does not reveal a crypto private key by itself, but it can identify people worth targeting.
Bitcoin users should never share a wallet recovery phrase, private key, authentication code, or screen-sharing session with a person who contacts them unexpectedly. A legitimate financial company does not need a recovery phrase to verify a customer or reverse a transaction. The safest response is to close the message, independently access the relevant service, and verify whether any action is actually required.
Passkeys can reduce exposure to password phishing because they are tied to the legitimate site or app rather than a copied login page. Customers who use password managers should understand how passkeys move between password managers before changing devices or security tools. The main limitation is that passkeys do not stop a user from approving a fraudulent payment or sharing sensitive documents, so careful verification remains necessary.
What remains unknown about the Revolut data breach?
The Revolut data breach still has 3 major unanswered questions: the number of affected customers, the identity of the government agency whose domain was abused, and the exact customer records disclosed in each case. Revolut has described the affected group as very limited, but it has not published a customer count. The company also has not publicly named the government entity connected to the compromised or abused email account.
The lack of a public total makes it difficult to measure the incident against larger financial-data breaches. The more immediate issue for an individual customer is whether Revolut contacted them and which data categories the company identified in that notice. Customers should preserve official messages, record suspicious communications, and report account concerns through verified support channels.
Revolut’s response indicates that the company treated the event as a legal-process impersonation incident, not a customer-account intrusion. That distinction explains why password resets alone are not a complete response. The most sensible approach is to secure account access, monitor for targeted fraud, and take identity-protection steps when identity documents or detailed financial records were included.
FAQ
Was Revolut hacked?
Revolut says its systems, customer accounts, and customer funds were not hacked in this incident. Revolut says fraudsters obtained records by sending fake legal requests from an email account on a legitimate government domain.
What data was exposed in the Revolut data breach?
Revolut says potentially exposed data included names, dates of birth, addresses, phone numbers, passports or driver’s licenses, verification selfies, statements, IBANs, withdrawal records, and transaction histories. The company said Bitcoin activity may also have been included in complete transaction histories.
Should Revolut customers change their passwords?
Revolut customers should change passwords if they reused the same password elsewhere or suspect an account-security issue. Revolut says the incident did not compromise customer accounts, but a unique password and stronger account verification can reduce follow-on phishing risk.
Can exposed passport information lead to identity theft?
Yes, exposed passport or driver’s license information can increase identity-theft risk because criminals can use detailed personal information in fraudulent applications or impersonation attempts. Customers whose documents were involved should monitor credit reports and consider a fraud alert or credit freeze.
How can Revolut customers verify a breach-related message?
Revolut customers should verify a breach-related message by opening the Revolut app directly or using an independently located official support channel. Do not use links, attachments, phone numbers, or login prompts included in an unexpected email or text.
