All stories
Big Tech

Revolut Confirms Major Data Breach Exposing Passport Copies and Bitcoin History

Digital banking giant Revolut has confirmed a significant customer data breach, revealing highly sensitive personal and financial information, including passport copies and complete Bitcoin transaction histories, was mistakenly handed over to an unauthorized third party through a sophisticated impersonation attack.

By TECH NEWS Editorial·Source:TechCrunch·4 min read·34m ago

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Revolut Confirms Major Data Breach Exposing Passport Copies and Bitcoin History

Revolut, the digital banking giant, has confirmed a significant customer data breach, revealing that highly sensitive personal and financial information, including passport copies and complete Bitcoin transaction histories, was mistakenly handed over to an unauthorized third party. The incident, disclosed on September 12, 2026, stems not from a direct hack of Revolut's systems, but from a "sophisticated external impersonation attack" where a fraudulent request, deceptively originating from a legitimate government agency's email domain with valid authentication credentials, bypassed internal verification processes. This cunning social engineering tactic exploited institutional trust, leading Revolut to believe the request was genuine and comply with the data disclosure before subsequently identifying the deception.

The breadth of compromised data is alarming, encompassing full names, dates of birth, occupations, postal and email addresses, phone numbers, copies of identity documents such as passports and driving licenses, verification selfies, International Bank Account Numbers (IBANs), account-opening dates, account statements, withdrawal records, and a full ledger of transaction history, crucially including Bitcoin activity and associated wallet reference numbers. While Revolut maintains that customer funds, passwords, login credentials, and biometric facial telemetry data remain secure, the sheer volume of personally identifiable information (PII) exposed presents a grave risk. Initial reports, spurred by on-chain investigator ZachXBT, suggest the attack was limited in scope, potentially targeting high-net-worth individuals, though Revolut has refrained from disclosing the precise number of affected customers or the specific government agency whose domain was exploited, citing an ongoing police investigation.

This incident matters profoundly for users, who are now at elevated risk of identity theft, highly personalized phishing attacks, and financial fraud. The combination of verified identity documents, selfies, and comprehensive financial records, including cryptocurrency holdings, provides malicious actors with an almost complete digital profile, enabling sophisticated account takeover attempts or the creation of synthetic identities. The assurance that "no funds were accessed or stolen" offers little comfort when the bedrock of personal identity and financial privacy has been so thoroughly undermined. For a generation increasingly reliant on digital-first financial services, the erosion of trust in a prominent fintech player like Revolut could have lasting repercussions, forcing users to reconsider the security promises of neobanks.

On an industry level, this breach highlights a critical vulnerability that transcends technical safeguards: the human element and the integrity of institutional communication channels. Unlike traditional cyberattacks that exploit system flaws, this "trust abuse" attack demonstrates how sophisticated social engineering can bypass even robust cryptographic and infrastructure security by weaponizing legitimate processes. This vector is not new; similar attacks leveraging compromised government or law enforcement email systems have previously impacted major tech entities like Meta, Apple, Discord, and Snap in 2022. Revolut's experience serves as a stark reminder that fintech firms, handling vast amounts of sensitive financial and personal data, are prime targets, with the average financial services data breach costing an estimated USD 5.56 million in 2025—one of the highest across all sectors.

Revolut's history includes prior security challenges, such as a social engineering attack in September 2022 that affected over 50,000 users and a 2023 flaw in its US payment system that led to a reported $20 million loss due to incorrect refunds. While these incidents differed in their technical specifics, they collectively paint a picture of an organization grappling with evolving threat landscapes. Compared to rivals, this type of sophisticated impersonation attack underscores a systemic challenge facing any entity that routinely processes lawful data requests from authorities. The ease with which a compromised or spoofed government email domain can trick seemingly secure internal protocols points to a widespread vulnerability in the verification workflows designed for legal compliance.

Looking ahead, the fallout for Revolut will likely involve intense scrutiny from regulators, including data protection authorities and financial watchdogs, who demand prompt incident reporting and robust response strategies under frameworks like GDPR. The company has already notified relevant agencies and affected customers, but the lack of transparency regarding the number of individuals impacted and the specific agency involved may invite further questions. Beyond immediate damage control, Revolut must re-evaluate and significantly harden its protocols for authenticating official data requests, potentially implementing multi-factor verification beyond simple domain authentication, such as out-of-band communication with known contacts within government agencies. The incident also necessitates enhanced employee training on recognizing sophisticated social engineering tactics, reinforcing that human vigilance remains the last line of defense against attacks that exploit trust rather than code. The fintech industry at large must absorb this lesson, moving towards a paradigm where every official request is treated as both a privacy and security event, requiring rigorous, multi-layered validation to prevent future exploitation of institutional trust.

Sources