The Revolut data breach released customer identity documents to a criminal posing as a government agency. The fraudulent request arrived from a genuine government email domain and passed authentication checks, so the London-based digital bank fulfilled it. Revolut disclosed the incident on 12 September 2026 and says its systems and funds are untouched.

What Was Taken

The notification Revolut emailed affected customers sets out identity and contact details, with financial records flagged as possibly included. Not every item now circulating has been confirmed by the company itself.

DataStatus
Full name, date of birth, occupationListed in Revolut’s notification
Postal address, email address, phone numberListed in Revolut’s notification
Passport or driving-licence copiesListed in Revolut’s notification
Identity-verification selfiesRevolut says these may have been included
Account statements, transaction historiesRevolut says these may have been included
IBANs, withdrawal records, Bitcoin transaction historyReported from a notification copy shared publicly by a recipient

The distinction matters more here than in an ordinary breach. A password can be changed in seconds. A passport number, a date of birth and a photograph of your face taken for identity verification cannot be reissued on demand, and they are exactly the package a fraudster needs to open an account somewhere else in your name.

How the Attacker Got the Data Without Hacking Revolut

There was no intrusion. Banks receive lawful data requests from tax authorities, police and regulators as routine business, and an attacker exploited that process rather than Revolut’s code.

Revolut told TechCrunch it had identified “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information”. In its account to BleepingComputer, the company added that “as the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request”.

In plain terms, the email came from a real government domain and the technical checks that confirm a sender is who it claims to be all passed. Revolut says it blocked the address once it spotted the pattern, and alerted the government agency concerned, law enforcement, data protection authorities and financial regulators.

Who Is Affected, and How to Tell

Revolut says a limited number of customers were involved and has contacted them directly. There is no self-service checker, so the email is the only signal. For scale, Revolut’s own figures put its customer base above 70 million as of January 2026, which makes “limited” an unhelpfully wide word.

Two things follow from that. If no notification has reached you, Revolut has not placed you in the affected set. If one has, treat it as genuine only after opening the Revolut app yourself and checking the in-app message centre, because a breach of this kind is immediately followed by people impersonating the bank.

The on-chain investigator known as ZachXBT has described the incident as limited in scale but aimed at high-net-worth users. Mark Karpelès, the former chief executive of the collapsed Mt. Gox exchange, has said publicly that he was among those notified. Revolut has not confirmed any targeting pattern.

What to Do If Revolut Emailed You

  1. Read the notification for the exact field list: Revolut’s emails vary by customer, and whether your selfie and statements were included changes what you are exposed to.
  2. Treat every inbound contact as hostile: anyone who calls or messages quoting your real address, occupation and recent transactions is not proving they are Revolut. Hang up and use the in-app chat.
  3. Never approve an in-app prompt you did not start: no genuine bank asks a customer to authorise a transfer, a card change or a device addition to keep an account safe.
  4. Move authentication off SMS: a leaked passport copy and date of birth are the material used to talk a mobile operator into a SIM swap, which defeats text-message codes.
  5. Report the exposure where you live: data protection authorities in the UK and EU take reports from individuals, and a filed report creates a record if your documents surface later.

Our earlier report on the IDScan data breach covers why a credit freeze does not address a leaked identity document, which is the same limitation customers face here.

The Ransom Demand Is Reported, Not Confirmed

Several crypto-focused outlets report that the attackers are demanding more than 10,000 bitcoin, worth roughly $780 million at the time of those reports, and are threatening to keep releasing data until they are paid. Help Net Security traces the threat to a Reddit post.

Revolut has not confirmed that a ransom was demanded, has not authenticated any of the material circulating online, and has not said whether the samples posted so far come from this incident. None of the wire services or security publications that carried Revolut’s statement have independently verified the figure. Treat it as an unverified claim until the company or a regulator addresses it.

What Revolut Has Not Said

  • The number of customers: “limited” is the only figure given.
  • The countries involved: Revolut operates across the UK, the European Economic Area and beyond, and has not named the affected markets.
  • The agency impersonated: Revolut has declined to identify it.
  • The dates: Revolut has not said when the fraudulent requests were received or how long they were fulfilled before detection.

Where the Investigation Stands as of 15 September 2026

As of 15 September 2026, Revolut has issued a statement, notified the customers it identified and referred the matter to law enforcement and to data protection and financial regulators. No regulator has announced a formal investigation, no customer total has been published, and no fine or enforcement action has been proposed.

The obvious open question is whether the same fraudulent-request technique has worked against other banks. Because the attack targets a legal process rather than a software flaw, there is no patch to apply and no version number that marks a firm as safe. Revolut has not said what it has changed about how it verifies such requests.

Frequently Asked Questions

Was Revolut Hacked in the Revolut Data Breach?

No. Revolut says its systems were not compromised and customer funds are unaffected. The data was released by Revolut staff in response to requests that arrived from a genuine government email domain and passed authentication checks.

How Do I Know If I Was Affected?

Revolut says it contacted affected customers directly by email. There is no public lookup tool. Verify any message by opening the Revolut app yourself rather than following a link.

How Many Customers Were Affected?

Revolut has not said. Its only description is “a limited number of customers”. Independent estimates circulating online have not been confirmed by the company or by any regulator.

Was Any Money Stolen?

Revolut says customer funds are unaffected. The incident released personal and account information rather than moving money out of accounts.

Is the 10,000 Bitcoin Ransom Demand Real?

It is unconfirmed. The claim comes from posts circulating online and has been repeated by crypto-focused publications. Revolut has neither confirmed a ransom demand nor authenticated the leaked samples.