LmCast :: Stay tuned in

Revolut discloses data breach exposing financial info, passports

Recorded: Sept. 14, 2026, 9:09 a.m.

Original Summarized

Revolut discloses data breach exposing financial info, passports

News

Featured
Latest

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Artifactory flaws chained in attacks deploying backdoor malware

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

September Windows Server updates break Remote Desktop Services

Revolut discloses data breach exposing financial info, passports

Microsoft: September updates break audio on some Windows PCs

CISA: Hackers now exploit max severity GitLab flaw in attacks

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityRevolut discloses data breach exposing financial info, passports

Revolut discloses data breach exposing financial info, passports

By Sergiu Gatlan

September 14, 2026
04:48 AM
0

Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency.
Revolut operates in over 160 countries and regions and offers banking, money management, and investment services to more than 80 million customers worldwide, including 800,000 business customers.
In emails sent to affected customers, the company said that the attacker requested the personally identifiable information (PII) via email using a government agency's domain.
"Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency's email domain," it told affected customers. "As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request."
Revolut says that the data sent to the threat actors includes affected individuals' identity details (i.e., full name, date of birth, occupation), contact details (postal address, email address, and telephone number), as well as document and verification data such as copies of your identity documents (passport and/or driver's license) and facial verification images (selfies provided for Know Your Client verification when opening an account).
The exposed information also includes account statements (including IBAN numbers), withdrawal records, and full transaction history (including Bitcoin transactions).
The company told Reuters that the resulting data breach affects a "very limited" number of customers, but has refused to share an exact number.
"Revolut systems and customer funds are unaffected. Upon detection, we immediately blocked the address and alerted the relevant ⁠government agency as well as enforcement agencies, data protection, and financial regulators," a Revolut spokesperson said.
Crypto fraud investigator ZachXBT said over the weekend that while the breach likely affects a limited number of Revolut customers, "it seems to have been targeted at high net worth users."
A Revolut spokesperson was not immediately available for comment when BleepingComputer reached out for more details about the incident.
Four years ago, Revolut disclosed another data breach after attackers stole the personal, contact, and financial information of 50,150 customers in September 2022.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
220 million traveler records exposed in Vietnam-linked APIS leakShinyHunters extortion gang claims Odido breach affecting millionsToy-making giant Hasbro disclose data breach affecting employeesCarhartt data breach exposes information of 12.9 million accountsATF confirms “major incident” after recent Qilin breach claims

Bank
Banking
Breach
Data Breach
Finance
Passport
Personally Identifiable Information
Revolut

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Hackers abused Claude to extract secrets from 1.8M Android apps

GitLab urges users to patch max severity path traversal flaw

Sponsor Posts

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Overdue a password health-check? Audit your Active Directory for free

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Fintech company Revolut disclosed a data breach that exposed sensitive customer information, including financial details and passport data, following a compromise orchestrated by a threat actor impersonating a government agency. Revolut operates across more than 160 countries, serving over 80 million customers globally, encompassing 800,000 business customers. The attackers obtained personally identifiable information (PII) through an unauthorized email account utilizing an official government agency's domain, which led to the fulfillment of a request under the reasonable belief that the request was authentic.

The specific data compromised includes identity details such as full names, dates of birth, and occupations, along with contact information including postal addresses, email addresses, and telephone numbers. Furthermore, the breach involved highly sensitive document and verification data, specifically copies of identity documents like passports and/or driver's licenses, as well as facial verification images used for Know Your Client verification when opening accounts. Financial records exposed also included account statements with IBAN numbers, withdrawal records, and comprehensive transaction histories, including Bitcoin transactions.

Revolut stated that the breach impacted a very limited number of customers, although an exact figure was withheld. The company assured that its systems and customer funds remained unaffected and immediately implemented countermeasures upon detection, which involved blocking the malicious address and alerting relevant government agencies, enforcement bodies, data protection authorities, and financial regulators. An investigation by crypto fraud investigator ZachXBT suggested that while the breach likely targeted a limited customer base, it appeared to focus on high net worth users. This incident follows a previous data breach disclosed by Revolut four years earlier in September 2022, in which attackers had previously stolen personal, contact, and financial information from over 50,150 customers.