Live Cybersecurity News Ticker | Codekeeper

Revolut Data Breach Exposed Passports to a Fake Government Email

Written by Content Team | Sep 14, 2026, 5:53:49 AM

Revolut has confirmed a data breach that exposed highly sensitive customer information — not through a system hack, but because someone tricked the company into handing it over. Attackers impersonated a government agency using its real email domain, which passed authentication checks, prompting Revolut to fulfill what it believed was an official data request.

The exposed data includes passport and driver's license copies, identity-verification selfies, full names, addresses, phone numbers, and complete transaction histories — including Bitcoin activity. Credentials, passcodes, and biometric face templates were not taken. No core systems or customer funds were compromised, Revolut says.

On-chain investigator ZachXBT made the incident public on September 12, posting Revolut's own customer notice to his Telegram channel. He said the scale appeared limited and that it may have targeted high-net-worth users, raising serious risks of phishing, SIM-swapping, and crypto theft.

Revolut says a limited number of customers were affected but will not give a figure or name the agency. Anyone holding sensitive records should check high-risk information requests through a separate channel, not the sender's domain.

Source: Cybersecurity News