A breach notification circulating among affected customers confirms that identity documents, facial verification selfies, IBANs, and complete transaction histories, including Bitcoin, left Revolut’s hands after the company was reportedly tricked by fraudulent government correspondence. Here’s what was exposed, why the notice’s wording matters legally, and what customers and fintechs should do next.
Sometime in the past 48 hours, Revolut customers began sharing a breach notification that reads less like a routine security update and more like an inventory of everything a bank knows about you. The notice lists four categories of compromised data: identity details (full name, date of birth, occupation), contact details (postal address, email, telephone number), document and verification data (copies of passports and driver’s licences plus the facial verification selfie submitted at onboarding), and financial data (account statements including IBAN, account status, opening date and wallet reference number, withdrawal records, and the full transaction history, Bitcoin included).
Posts summarising the incident on X were blunter than any press release: Revolut, users wrote, “got phished by some fake govt mail and they just handed over our data,” listing bank statements, selfies, wallets, and transaction history. If that holds up, this incident belongs to a class of breach that perimeter security can’t stop, because nothing was hacked in the traditional sense. The data was handed over by people who believed they were complying with an official request.
The timing makes this worse. It comes weeks after a threat actor advertised 75 million alleged Revolut records on a cybercrime forum for $500 (a claim Revolut disputed after finding no indicators of compromise and no valid identifiers in the samples), and months after a former employee allegedly tried to extort a customer by threatening to leak KYC data unless paid in cryptocurrency. Add a fraud wave in Jersey, where 75% of scam reports over four weeks involved Revolut accounts and roughly £180,000 was lost, and you get a threat ecosystem already primed to use exactly the kind of data this notification describes.
Revolut’s Official Statement is as Follows:
Revolut received a request for information disguised as a legitimate government agency request. The request originated from an unauthorized email account created directly within an official government authority’s domain infrastructure. The communication carried genuine domain authentication credentials leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request.
Once we became aware of the issue, we independently contacted the relevant government agency to validate the request, ultimately alerting the authority to the unauthorized account apparently operating within their domain. Upon confirming the compromise, Revolut immediately blocked the address across all internal systems, initiated notifications to relevant regulators, and applied precautionary protection measures for affected customers.
What we know, and what is still reported rather than confirmed
Let’s be precise about attribution, because breach coverage collapses when speculation hardens into fact. What is documented: affected customers received a notification enumerating the four data categories above, including the explicit statement that “no biometric facial telemetry data was involved or compromised.” Screenshots of that notice and of customer posts describing a fake-government-email phishing vector began circulating publicly on September 11 to 12, 2026. What is not yet independently confirmed in indexed reporting: the number of affected customers, the specific government body impersonated, and the internal workflow through which the data was released. At the time of writing, the most detailed primary account of what was taken is the notification itself, so we’re treating the “fake government mail” vector as a well-sourced customer report rather than a company confirmation.
The data categories in the notice are specific, internally consistent with Revolut’s product set (IBANs from its Lithuanian-licensed banking entity, wallet references and Bitcoin history from its crypto custody service), and materially more sensitive than anything exposed in the company’s 2022 incident. Whether the handover originated with a phished support agent, a compromised back-office mailbox, or a manipulated legal-request process, the outcome is identical: a complete KYC and financial dossier on an unknown number of customers now sits outside Revolut’s control.

The attack vector: why “handed over” is more dangerous than “hacked”
Most breach post-mortems describe an intrusion chain (initial access, persistence, lateral movement, exfiltration), and each stage leaves telemetry that detection engineering can catch. A social-engineering handover inverts that model. The attacker sends correspondence impersonating a government authority (a regulator, tax agency, or law enforcement body issuing what appears to be a lawful demand for customer records), and an employee trained to cooperate with official requests complies. Every action in the chain is authorised: the mailbox login is legitimate, the database query is legitimate, the export is legitimate. EDR never fires, because from the infrastructure’s point of view, work is simply being done.
This is why government-impersonation phishing has become a priority threat against regulated industries. The pretext exploits the one behaviour security awareness training struggles to eliminate: deference to authority under time pressure. It targets the process rather than the password. Multi-factor authentication is irrelevant when the credential was never stolen; the attacker never needed a session cookie because the data arrived as an attachment. Revolut has form here: its September 2022 breach, which exposed 50,150 customers’ names, addresses, email addresses, phone numbers, partial card data, and past transactions, began with a phished employee credential and a “highly targeted” social-engineering campaign, and was subsequently investigated by Lithuania’s State Data Protection Inspectorate, the lead supervisory authority for Revolut’s EEA entities.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →The 2026 twist is the payload. Four years ago, attackers walked away with contact details and masked card fragments: useful phishing fuel, but limited. This time, according to the notification, they walked away with the onboarding file itself: the government-grade identity proof and the live face image that banks and other exchanges use to decide whether an applicant is really you.
Inside the notification: a category-by-category risk analysis
The notice’s four data points breached are as follows:
Identity details: full name, date of birth, occupation
On their own these are commodity data. Combined with the rest of the package they become the skeleton of a synthetic identity: enough to answer knowledge-based verification questions at other institutions, to pre-fill credit applications, and to make every subsequent phishing contact feel bureaucratically authentic. Occupation is an underrated field here: it tells a fraudster whether you’re worth a business email compromise campaign, whether a “payroll update” pretext will land, and which institutions you’re likely to hold accounts with.
Contact details: postal address, email address, telephone number
This is the targeting layer. Physical address enables interception-based fraud and lends credibility to vishing calls (“we’re calling about your account at [your street]”). The email and phone number are the delivery channels for the follow-on campaign, and history shows these arrive fast: after the 2022 breach, a phishing wave hit Revolut’s entire customer base, not just the 50,150 affected, using real account attributes to manufacture trust.
Document and verification data: passport or driver’s licence copies plus the onboarding selfie
This is the crown-jewel category, and the reason this story matters beyond Revolut’s customer base. A high-resolution scan of a passport or driver’s licence is a forgery kit: the document template, security-feature layout, and a victim’s biographic data are everything a counterfeit operation needs. The selfie is more damaging still. KYC selfies exist to prove that a live human matches the document; in criminal hands, the same image trains presentation attacks against liveness detection elsewhere. Telegram-based KYC-bypass services already sell deepfake injection tooling that feeds synthetic faces or replayed video into identity-verification SDKs on jailbroken devices, and the broader market has been reinforced by mega-leaks of verification imagery, from the IDScan.net-style driver’s licence dumps to the nine-million-image facial-recognition breach reported in August 2026. A leaked selfie doesn’t expire, can’t be rotated, and now travels with the exact passport it was matched against.
The notification’s careful rider, “no biometric facial telemetry data was involved or compromised,” is a legally loaded sentence. We unpack it below.
Financial data: IBAN, account status, opening date, wallet reference, withdrawal records, full transaction history including Bitcoin
Read this list as an attacker’s dossier and it’s close to complete. The IBAN enables fraudulent SEPA direct-debit mandates (victims have refund rights, but only if they notice within the windows). Account status and opening date are precisely the facts a support-desk social engineer needs to pass verification at Revolut or at correspondent institutions. The wallet reference number is the join key between the fiat file and the crypto file: it ties the internal custody account to the customer record. Withdrawal records reveal liquidity and cash-out rhythm: when you have money and when you move it, the exact targeting data extortionists prize. And the full transaction history, Bitcoin included, does the most irreversible damage of all: it permanently binds your legal identity to your on-chain pseudonyms.
“No biometric facial telemetry was compromised”: reading the fine print like a regulator
That clause isn’t marketing. It’s a GDPR boundary marker. Under Article 9, biometric data processed to uniquely identify a person is a special category attracting heightened protection and heavier penalties. A raw selfie is an image; a biometric template (the mathematical feature map, liveness scores, and depth or motion telemetry a verification SDK generates when it analyses that image) is biometric data in the strict sense. By stating that no telemetry was involved, Revolut is asserting that the exposed asset is the photograph, not the derived template, and therefore that the incident doesn’t constitute a special-category biometric breach.
The distinction is legally real and practically thin. Attackers don’t need your feature vector to impersonate you; they need pixels. A stolen selfie plus a stolen passport scan supports document replays, face-swap injection into verification flows, and the synthesis of convincing video for vishing-adjacent scams. Regulators, including European data protection authorities following EDPB guidance on facial recognition, assess risk by what the data enables, not by its format. Expect the Lithuanian State Data Protection Inspectorate, which published details of the 2022 breach and opened a formal investigation into Revolut’s handling of it, to test exactly that point if this notification triggers an Article 34 assessment, and its specificity suggests it has.
The Bitcoin problem: why “including Bitcoin” is the sentence crypto holders should reread
Bitcoin’s ledger was always public; privacy on-chain was never about hiding transactions but about hiding who owns the addresses. Every defence a holder relies on, address rotation, separation of funds, pseudonymous wallets, depends on the identity-to-address map staying secret. A leaked transaction history from a KYC’d custodian destroys that secrecy in one document: it states which verified individual controlled which wallet references, when funds arrived, how large the positions were, and where they went.
Because blockchains are append-only, that linkage can’t be undone. Chain-analysis techniques such as common-input-ownership clustering and change-address heuristics let anyone who holds the identity map extend it forward across years of future transactions. The practical consequences are unglamorous and severe: dusting and targeted-phishing campaigns aimed at known holders, extortion lists sorted by balance, and, as the February 2026 case showed, when a trader alleged a former Revolut employee threatened to publish his KYC file and contacted his relatives unless a crypto ransom was paid, blackmail material that arrives pre-verified by the institution itself. Revolut reported that matter to law enforcement and maintained that its controls operated as intended; the alleged incident nonetheless showed attackers pricing KYC dossiers as ransom assets months before this notification existed.
Revolut’s incident timeline
One breach is an event; four is a trend. The record, as publicly reported:
Date Incident Reported impact Sept 2022 Social-engineering attack; phished employee credential; database access 50,150 customers (0.16%); contact + partial card data + past transactions; Lithuanian SDPI investigation July 2023 Exploited flaw in US payment processing ~$20M stolen via erroneous refunds Feb 2026 Alleged extortion by former employee threatening KYC leak Individual customer targeted; crypto ransom demanded; referred to law enforcement July 2026 Forum listing claiming 75M records for $500 Revolut found no breach indicators; researchers suspect aggregated/fabricated data Aug to Sept 2026 Jersey vishing wave impersonating Revolut fraud teams 75% of scam reports over 4 weeks; ~£180,000 lost Sept 2026 Fake-government-email phishing; customer data handover (this incident) KYC documents, selfies, IBANs, full txn history incl. Bitcoin; scale unconfirmed
Read together, the timeline shows both sides of the modern threat model converging on the same asset: outsiders phishing their way toward customer records, and insiders (or ex-insiders) treating those records as saleable inventory. It also shows the follow-on economy working exactly as designed: breached attributes from earlier incidents supplied the authenticating detail for the Jersey vishing campaigns.
Regulatory exposure: GDPR, DORA, and the Lithuanian supervisory chain
Revolut’s EEA operations run through Lithuanian-licensed entities supervised by the Bank of Lithuania and the ECB, with the State Data Protection Inspectorate acting as cross-border lead supervisory authority for data protection, which is where Articles 33 and 34 of the GDPR bite. A breach of this sensitivity (identity documents, facial images, complete financial history) sits squarely in “high risk” territory, obliging communication to affected data subjects in clear language. The notification’s plain-English category list is, to its credit, exactly what Article 34 contemplates, and a marked improvement on the vaguer 2022 emails that drew customer criticism at the time.
Beyond GDPR, Revolut Bank UAB is in scope for DORA (Regulation (EU) 2022/2554), which forces major ICT-related incident reporting and, more importantly for this case, demands that operational risk from social engineering of critical processes be governed, tested, and documented. UK-facing operations add FCA principles and UK GDPR obligations overseen by the ICO, which was also engaged in 2022. The sanction ceiling (up to 4% of global turnover or €20 million under GDPR, whichever is higher) is theoretical; the realistic costs are compulsory remediation, supervisory scrutiny of the legal-request workflow, and civil claims under Article 82 for material and non-material damage, which collective-claims firms will already be scoping.
If you received this notification: a prioritised response checklist
Treat the next 90 days as a hostile information environment. Work top to bottom.
- Assume every inbound contact is fraudulent until proven otherwise. Revolut will not call to ask for codes, passwords, or approvals. Anyone who does is attacking you, and they now know enough about your account to sound legitimate. Verify through the app’s official chat or a number you typed in yourself.
- Harden the account itself. Enable app biometric lock and a strong passcode, move your email to a unique password with phishing-resistant 2FA (a passkey or hardware key, not SMS), and review active sessions and linked devices.
- Register for fraud protection. In the UK, consider CIFAS Protective Registration; in the US, freeze your files at all three bureaus; elsewhere, set credit-file alerts. Your name, DOB, and address are now a pre-approved application kit.
- Watch the rails, not just the balance. Set transaction alerts, scrutinise statements for unfamiliar SEPA direct debits (unauthorised debits carry a 13-month claim window; authorised-but-contested ones, eight weeks), and never move money to a “safe account,” which doesn’t exist.
- Treat your on-chain history as attributed from now on. Use fresh receiving addresses, ignore dust transactions and “wallet verification” messages, avoid discussing holdings in any channel, and if you hold materially, review your operational security with the assumption that your balance range is known.
- Monitor for identity misuse for a year. Unexpected credit declines, collection letters, or tax correspondence in your name are the lagging indicators of document fraud, so check your credit file quarterly.
- Preserve evidence and know your rights. Keep the notification, log every suspicious contact, and remember that GDPR Article 82 gives you a compensation route and Article 77 a complaint route to your supervisory authority.
What fintechs must fix: KYC stores are crown-jewel data, and they’re managed like attachments
For security leaders, this incident is a control-design case study. Start with the request channel: any email asserting government or regulator authority should be unverified by default, answered only through pre-registered out-of-band channels (a callback to a published switchboard, an authenticated regulator portal, or a signed-correspondence register), with dual-control approval before a single record leaves the building. Then fix the egress path: bulk exports of KYC media from support consoles should be technically difficult, ticketed, approved, and alerted on, because a handover breach is caught by data-loss prevention and access analytics, not by endpoint tooling.
Retention is the third lever, and the one nobody wants to pull. AML rules require keeping records, but they don’t require keeping every artefact in its most dangerous format forever: extract the data fields, verify the document and face, then apply a minimisation schedule, watermarked, access-logged, tightly permissioned storage for images, with raw selfies and templates purged once the verification decision is final and the retention basis expires. Layer on phishing-resistant MFA for staff, vishing and quishing drills that include the legal-request desk, anomaly detection for burst reads against KYC object stores, and dark-web monitoring that treats KYC-pack listings (genuine or fabricated, as July’s $500 claim showed) as an early-warning feed. Firms that get ahead of the next decade of identity fraud will be the ones that stop treating onboarding imagery as a by-product and start treating it as the most dangerous material they hold.
Frequently asked questions
Was my money stolen in this Revolut breach? There’s no evidence that funds were accessed or moved; the exposure is data, not balances. The financial risk is indirect but real: the stolen attributes are precisely what fraudsters use to engineer transfers, approve debits, and take over accounts elsewhere.
How do I know if I’m affected? Revolut is notifying affected customers directly, and the notification enumerates the exact categories taken. If you haven’t received one, you’re likely outside this incident’s scope, but stay alert, because follow-on phishing after Revolut breaches has historically targeted the whole customer base, not only the compromised subset.
What does “no biometric facial telemetry was compromised” actually mean? It means the derived biometric artefacts (feature maps, liveness scores, measurement data generated during verification) weren’t touched; only the raw selfie image was. Legally that keeps the incident outside GDPR Article 9’s special-category biometric regime; practically, the image alone still enables deepfake and presentation attacks.
Can a leaked selfie and passport scan be used to open accounts in my name? Yes. Forgery tooling and deepfake injection kits that defeat liveness checks on verification SDKs are commercially available on criminal markets, which is why fraud alerts and credit-file monitoring matter more than password changes after a breach like this.
Is my Bitcoin transaction history now public? The ledger was always public. What’s changed is that your verified identity is now linked to your wallet references and history in criminal hands. That linkage is permanent and extends forward to future transactions through standard chain-analysis clustering.
Can I claim compensation? GDPR Article 82 provides for compensation for material and non-material damage caused by an infringement, and Article 77 lets you complain to a supervisory authority, the Lithuanian State Data Protection Inspectorate for EEA customers, the ICO for UK customers. Keep records of any fraud or distress you suffer as a result.
The bottom line
Every ingredient of this incident has been visible for years: KYC files as the single most valuable object in the fraud economy, government impersonation as a phishing pretext that defeats MFA without ever touching it, and blockchain permanence turning one leaked statement export into a lifelong identity-to-wallet map. What’s new is the completeness of the package described in Revolut’s notification: document, face, fiat history, and crypto history in one handover. For customers, the response is disciplined skepticism and monitoring, because the data can’t be un-leaked. For the industry, it’s a reminder that the weakest link in a bank’s security architecture is still the well-meaning employee holding a letter that looks official, and that the strongest defense is a process where no single human, and no single email, can move a customer’s identity out the door alone.









