VYPR
breachPublished Sep 13, 2026· 1 source

Revolut Data Breach Exposes Customer Passport Copies and Transaction Histories

Financial technology firm Revolut has disclosed a data-security incident where sensitive customer information, including passport copies and transaction histories, was exposed via a fraudulent request impersonating a government agency.

Financial technology giant Revolut has revealed a significant data-security incident that led to the exposure of sensitive customer information, including Know Your Customer (KYC) documents and detailed transaction histories. The breach occurred not through a compromise of Revolut's core systems or customer accounts, but via a sophisticated social-engineering attack. Threat actors successfully impersonated a legitimate government agency, submitting a fraudulent request that, due to valid domain-authentication credentials, was mistakenly fulfilled by Revolut.

The exposed data is highly sensitive and includes full customer names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. More critically, copies of identity documents such as passports and driver's licenses, along with facial-verification images submitted during the onboarding process, were also disclosed. While Revolut stated that biometric facial telemetry was not involved, the loss of these documents poses substantial risks for identity theft and impersonation.

Beyond identity documents, the incident also compromised extensive financial records. This included account statements with IBANs, account status, opening dates, wallet reference numbers, withdrawal records, and complete transaction histories. Notably, the exposure of cryptocurrency transaction records, including Bitcoin activity, could provide attackers with detailed insights into users' financial behavior, wealth, and potential vulnerabilities for targeted scams.

Revolut has characterized the event as a social-engineering attack rather than a breach of its internal infrastructure. The company claims to have acted swiftly by blocking the unauthorized email source, notifying relevant authorities, and contacting affected customers. Revolut also emphasized that customer funds remain secure and its systems were not compromised.

However, the incident has reignited concerns about the security of mandatory KYC data collection practices across financial institutions, fintech platforms, and cryptocurrency services. On-chain investigators and cryptocurrency community figures have pointed out that the attack may have targeted high-net-worth individuals, a demographic particularly vulnerable to sophisticated phishing, SIM-swapping, extortion, and tailored cryptocurrency theft attempts.

The combination of compromised identity documents, personal contact details, account information, and transaction history provides attackers with a potent toolkit for crafting convincing social-engineering lures. Fraudsters could impersonate Revolut support, law enforcement, exchanges, or tax authorities, using the stolen personal data to lend credibility to their schemes.

This incident also highlights a critical vulnerability in how organizations handle information requests. Even when requests appear to come from authenticated email domains, the sender account itself may be unauthorized. The case underscores the necessity for organizations handling sensitive customer data to implement robust, out-of-band verification processes for high-risk information requests, rather than relying solely on sender identity or domain authentication.

The implications extend to the broader financial and regulatory landscape, potentially leading to increased scrutiny of data handling practices and security protocols within the fintech sector.

Synthesized by Vypr AI