Revolut Trickers Hand Over Passports and Crypto Data to Fake Officials

Revolut Trickers Hand Over Passports and Crypto Data to Fake Officials

2026-09-14 companies

London, Monday, 14 September 2026.
Fraudsters spoofed an official government agency domain to trick Revolut staff into handing over high-net-worth clients’ sensitive passports and full Bitcoin transaction records, leaving underlying customer funds unaffected.

Revolut Confirms Data Breach via Fake Government Requests

Fintech giant Revolut has confirmed a significant data breach after fraudsters tricked the platform into releasing sensitive customer information using fraudulent government data requests [1][2]. The incident, identified on 11 September 2026, involved an unauthorized third party utilizing a legitimate government agency domain email to submit requests that Revolut staff believed were genuine [1][4]. The company stated that systems and customer funds remain unaffected, but specific customer data was exposed during the interaction [2][6].

The Mechanics of the Fraud

The attack relied on sophisticated social engineering where the perpetrators gained access to or created an account inside an official government mailbox domain [4][6]. Because the request came from a real government agency email domain carrying valid credentials, Revolut’s compliance procedures flagged it as legitimate before releasing the data [1]. The company described the incident as a sophisticated external impersonation attack rather than a direct hack of their internal systems [1][2].

Company Response and Security Status

Revolut emphasized that customer funds were not affected and that the breach did not involve compromised servers or malware [4][6]. The company confirmed that credentials and biometric templates used for facial recognition remained secure, though verification photos themselves were among the data released [1][4]. Affected users began receiving individual notifications on 11 September 2026, advising them of the exposure [4][6].

Market Context and Valuation

This incident occurs as Revolut prepares for potential public listing plans, with previous reports targeting a valuation of up to $200 billion [2]. In July 2026, a secondary share sale valued the company at $115 billion, representing a significant increase from a $75 billion valuation in a November funding round [2][6]. The percentage increase from the November round to the July 2026 valuation is approximately 53.333 percent [2][6].

Industry Implications

Security experts suggest that such breaches highlight vulnerabilities in how financial institutions handle official requests for information [5][6]. Lukas Helminger, commenting on the incident, argued that banks should not need to store sensitive KYC data if Zero-Knowledge Proofs (ZKP) were utilized [5]. ZKP technology allows institutions to mathematically prove a user fulfills requirements, such as age or residency, without the sensitive data leaving the user’s device [5].

Sources


Data Breach Fintech Security