Skip to main content
LiMP VPN
All news

Revolut Breach: Fraudsters Stole Passports and IBANs 2026

Revolut Breach: Fraudsters Stole Passports and IBANs 2026

In short: On September 12, 2026, Revolut confirmed a data breach: fraudsters created an unauthorised email account within a real government agency's domain infrastructure, then tricked Revolut employees into handing over customer data. Passports, identity selfies, IBANs, and full transaction histories were exposed. Account funds were untouched — but personal data is now in criminal hands.

The attack: a fake government request

Unlike most data breaches, this incident involved no server intrusion and no code vulnerability. Attackers used a far simpler method: social engineering.

The mechanics: fraudsters created an unauthorised email account within the actual infrastructure of a legitimate government agency. Messages arrived from the real agency domain and carried valid DKIM/DMARC authentication headers — technically, everything looked official. Revolut staff, receiving what appeared to be a lawful government request, complied and transferred customer data. The deception was discovered only after Revolut independently contacted the actual agency. A previous social engineering attack against Revolut in 2022 affected approximately 50,150 users. For ongoing threat coverage, see the LiMP VPN news section.

What data was exposed

Revolut disclosed the full list of information transferred to the fraudsters:

  • Personal details: names, dates of birth, home and email addresses, phone numbers, occupation
  • Identity documents: passport or driver's licence copies, facial photographs taken during identity verification
  • Financial information: bank statements, IBANs, account opening dates, complete transaction history
  • Cryptocurrency records: in some cases, Bitcoin transaction data

Biometric templates (digital face-print data used by Face ID and equivalent systems) were not compromised — only the photographs taken at registration. Revolut describes the number of affected users as "limited" but refuses to disclose either a figure or the specific countries involved.

To understand the risk: a combination of passport scan + selfie + IBAN + transaction history is sufficient to pass identity verification at other financial services, or to open an account in someone else's name in jurisdictions with simplified online KYC.

Revolut's official position: money safe, data is not

The company confirmed the incident on September 12, 2026. Revolut stated it immediately blocked the compromised address, notified law enforcement and financial regulators in the relevant jurisdictions, and contacted affected customers directly.

The company's key reassurance: "banking infrastructure and user funds were not affected," and no unauthorised account access has been verified. There is no confirmed evidence, as of the date of disclosure, that the transferred data has been used for fraudulent transactions.

Security researcher ZachXBT suggested that the attackers may have specifically targeted high-net-worth clients with substantial cryptocurrency holdings — inferred from the transaction histories that were part of the breach. Revolut has not confirmed this theory.

Why this breach is dangerous even without a server hack

The conventional image of a data breach involves hacking, code vulnerabilities, a technical intrusion. The Revolut case illustrates a different reality: data can be obtained without ever touching a company's servers — by convincing an employee to fulfil a "legitimate" request.

This matters especially for financial applications. KYC (Know Your Customer) compliance requires collecting precisely the data that makes a breach most damaging: identity documents and facial photographs. Banks and fintech firms must collect and store this information — which is exactly why they become targets for social engineering.

Device and network-layer defences reduce some of the exposure. LiMP VPN encrypts your traffic and hides from your ISP and public networks the fact that you are using financial applications — making it harder to intercept session tokens or track financial activity. See plans from $0.99/month.

What to do if you are a Revolut customer

1. Check your email. Revolut promised to notify affected customers directly. If you received a notice, follow the instructions the company provides.

2. Enable strong authentication. In the Revolut app, confirm two-factor authentication is active. Change your password if you have not done so since 2024.

3. Watch for unexpected KYC requests. If you receive messages over the coming months asking you to complete identity verification at an unfamiliar service, it may be an attempt to open accounts in your name using the leaked documents. Verify senders through official channels only.

4. Never respond to "official requests" via phone or messaging apps. Real agencies and banks do not request sensitive personal data through unofficial channels. Any such request is a social engineering attempt.

Sources

Revolut Breach: Fraudsters Stole Passports and IBANs 2026