Revolut Breach: Fake Government Email Tricked an Employee Into Handing Over Customer Data
British fintech Revolut confirmed that an unauthorized third party obtained sensitive customer records — passports, driving licences, financial records —.

TL;DR
- —An employee handling the request released a batch of customer records believing the inquiry came from an authorized public authority.
- —The attacker didn't break into Revolut's systems; they broke the trust judgment of a single employee by impersonating the one institution employees are trained not to question: the government.
- —And it's a reminder that "breach" doesn't mean "backdoor" — it means "the wrong person got the right data," and the path there is often a convincing email and a busy, trusted employee.
The Incident Revolut — one of the world's largest digital banks by customer count, with roughly 80 million registered users — told reporters on September 12, 2026 that an unauthorized third party obtained sensitive customer information through a fraudulent request, not a direct hack. An employee handling the request released a batch of customer records believing the inquiry came from an authorized public authority. The deception hinged on a phishing email sent from a domain belonging to a legitimate government agency — a technically thin but socially devastating trick: the sender domain checked out, so the request carried an authority it didn't deserve. What Was Exposed Reporting across Reuters and other outlets describes an unusually broad data set for a fintech incident: Identity documents: passports and driving licences
Full names, dates of birth, occupation, home addresses
Email addresses and phone numbers
Financial records: IBANs, account status, opening dates, wallet reference numbers, account statements, withdrawal records
Transaction history — multiple outlets flag complete transaction histories, including Bitcoin activity, suggesting the affected accounts skew toward customers who use Revolut's crypto trading features Why This Matters: The Human is Always in the Loop This breach matters because every technical control money can buy was, presumably, in place — encryption, access controls, monitoring — and it didn't matter. The attacker didn't break into Revolut's systems; they broke the trust judgment of a single employee by impersonating the one institution employees are trained not to question: the government. This is the social-engineering pattern weaponized at the highest-stakes target: financial identity documents. And it's a reminder that "breach" doesn't mean "backdoor" — it means "the wrong person got the right data," and the path there is often a convincing email and a busy, trusted employee. What to Do Know what was exposed before you panic. Passports and licences are identity anchors: if you're among those notified, that's materially different from an email-only leak.
Freeze your credit. Financial records plus identity documents is the recipe for account takeover and synthetic-identity fraud.
Watch for follow-on phishing. Breach notifications themselves are a common second-wave phishing lure — verify any "remediation" email through Revolut's official app, never through links in a message.
For everyone else, the lesson is the process. Any institution that requests your data — government or otherwise — can be impersonated. Build a habit of verifying data requests through independent channels before trusting a sender, no matter how official the domain looks. The Pattern Revolut is a case study in the failure mode that no firewall prevents: the path of least resistance to sensitive data is a person. Government-impersonation phishing is the apex of that trend — it exploits the instinct to comply with authority, the one vulnerability no patch can fix. The countermeasures are procedural and human: independent verification, dual approval for releasing identity data, and an organizational culture where "that request looked official" is never a sufficient check. In a world where AI makes the fake indistinguishable, the human judgment step deserves — and now demands — the same rigor as the strongest encryption.