Data Breach

Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers

Revolut has disclosed a data-security incident in which sensitive customer information was released after the financial technology company received a fraudulent request that appeared to originate from a legitimate government agency. Here is the detailed breach report and the developments.

The incident reportedly exposed highly sensitive Know Your Customer (KYC) documentation and detailed financial records belonging to a limited number of users, including passport or driver’s license copies, identity-verification selfies, account statements, and complete transaction histories that included Bitcoin-related activity.

According to Revolut’s explanation, the disclosure did not result from a compromise of its core systems, mobile application, or customer accounts. Instead, the company said it was targeted through a sophisticated impersonation operation involving an unauthorized email account operating under an official government agency’s email domain.

Because the message carried valid domain-authentication credentials, Revolut believed it was handling an authentic legal or government information request and fulfilled it.

The response provided extensive information. It included customers’ full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers.

The exposed document and verification data reportedly included copies of identity documents, such as passports and driving licenses, along with facial-verification images submitted during onboarding.

Revolut highlighted that biometric facial telemetry was not involved or compromised, although the loss of document scans and verification selfies could still create serious identity-theft and impersonation risks for affected individuals.

Financial data included account statements containing IBANs, account status information, account-opening dates, wallet reference numbers, withdrawal records, and full transaction histories.

The inclusion of cryptocurrency transaction records, including Bitcoin activity, is particularly sensitive because it could help criminals profile victims’ wealth, trading behavior, wallet usage, and potential exposure to targeted scams.

Revolut described the event as a sophisticated social-engineering attack rather than a breach of its internal infrastructure. The company said it moved quickly to block the unauthorized email source, notify relevant authorities, and contact affected customers. It also maintained that customer funds remained safe and that its systems were not compromised.

However, the incident has triggered renewed concern over the security implications of mandatory KYC data collection across banks, fintech platforms, and cryptocurrency services. On-chain investigator ZachXBT and other cryptocurrency community figures highlighted claims that the operation targeted high-net-worth users, a group that faces elevated risks of phishing, SIM-swapping, extortion, physical threats, and highly tailored cryptocurrency theft attempts.

For impacted Revolut customers, the combination of identity documents, contact details, account information, and transaction history could provide attackers with the material needed to construct convincing social-engineering lures. Fraudsters may impersonate Revolut support staff, law-enforcement agencies, exchanges, or tax authorities while using personal information to make messages appear legitimate.

The case also demonstrates how trusted email domains can be abused when an attacker gains access to, or misuses, a legitimate organization’s mail infrastructure.

Even properly authenticated email can be malicious when the sender account itself is unauthorized. The incident underscores the need for organizations handling sensitive customer records to independently validate high-risk information requests through out-of-band channels, rather than relying solely on domain authentication or sender identity.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago