Revolut Handed Customer Passports to Scammers Using a Real Government Email Domain
September 13, 2026 – 4:06 pm
Credit: Shootdiem via Shutterstock.com
Revolut admitted to a data breach where they inadvertently provided sensitive customer information, including dates of birth, addresses, phone numbers, passports, and driving licenses, to criminals posing as a government agency. This occurred due to an "external impersonation scam" where a third party utilized a legitimate government domain in their email requests.
According to a Revolut spokesperson, their systems remained unaffected, and they promptly took action, blocking the domain, notifying affected customers, and alerting the relevant government agency. However, they have been tight-lipped about the extent of the breach, refusing to disclose the number of affected individuals or specific countries.
The breach was initially discovered by crypto investigator ZachXBT, who suggested it targeted high-net-worth individuals. This incident raises concerns given Revolut’s recent focus on attracting high-value customers with a £500,000 entry threshold for their private bank, as part of their preparation for a $200bn listing.
The company’s response, while prompt, has left many unanswered questions. European data protection laws mandate that companies notify their supervisory authorities and affected individuals within 72 hours of becoming aware of a breach. However, the public account remains limited to a spokesperson’s statement and an investigator’s post.
Customers who received notifications should assume their information is now publicly accessible.