Revolut Trickers Hand Over Passports and Crypto Data to Fake Officials
London, Monday, 14 September 2026.
Fraudsters spoofed an official government agency domain to trick Revolut staff into handing over high-net-worth clients’ sensitive passports and full Bitcoin transaction records, leaving underlying customer funds unaffected.
Revolut Confirms Data Breach via Fake Government Requests
Fintech giant Revolut has confirmed a significant data breach after fraudsters tricked the platform into releasing sensitive customer information using fraudulent government data requests [1][2]. The incident, identified on 11 September 2026, involved an unauthorized third party utilizing a legitimate government agency domain email to submit requests that Revolut staff believed were genuine [1][4]. The company stated that systems and customer funds remain unaffected, but specific customer data was exposed during the interaction [2][6].
The Mechanics of the Fraud
The attack relied on sophisticated social engineering where the perpetrators gained access to or created an account inside an official government mailbox domain [4][6]. Because the request came from a real government agency email domain carrying valid credentials, Revolut’s compliance procedures flagged it as legitimate before releasing the data [1]. The company described the incident as a sophisticated external impersonation attack rather than a direct hack of their internal systems [1][2].
Company Response and Security Status
Revolut emphasized that customer funds were not affected and that the breach did not involve compromised servers or malware [4][6]. The company confirmed that credentials and biometric templates used for facial recognition remained secure, though verification photos themselves were among the data released [1][4]. Affected users began receiving individual notifications on 11 September 2026, advising them of the exposure [4][6].
Market Context and Valuation
This incident occurs as Revolut prepares for potential public listing plans, with previous reports targeting a valuation of up to $200 billion [2]. In July 2026, a secondary share sale valued the company at $115 billion, representing a significant increase from a $75 billion valuation in a November funding round [2][6]. The percentage increase from the November round to the July 2026 valuation is approximately 53.333 percent [2][6].
Industry Implications
Security experts suggest that such breaches highlight vulnerabilities in how financial institutions handle official requests for information [5][6]. Lukas Helminger, commenting on the incident, argued that banks should not need to store sensitive KYC data if Zero-Knowledge Proofs (ZKP) were utilized [5]. ZKP technology allows institutions to mathematically prove a user fulfills requirements, such as age or residency, without the sensitive data leaving the user’s device [5].