Affected users were warned that their identification documents and account information may have been accessed.
Photo Credit: Unsplash/appshunter.io
The incident involved fraudulent information requests submitted by an unauthorised third party
FinTech and banking firm Revolut exposed sensitive customer information, including passport details, selfie authentication photos, and complete transaction history, after a fraudulent request that appeared to come from an official government agency. Customer information requests from a government agency's genuine email address passed Revolut's verification process, according to a post by the International Cyber Digest on Twitter. Revolut later stated that the requests were not genuine, and the compromised customers were informed about it on Friday. A limited number of customers were affected, said a spokesperson from Revolut.
The compromised data included personal identification and contact information such as date of birth, home and email address, and phone numbers, along with copies of identification documents such as passports and driving licenses. The compromised data may also include selfie authentication images, account statements, and transaction history, according to the notification sent out to affected users via email, as reported by TechCrunch.
:bangbang: BREAKING: Revolut handed over customers' passport copies, verification selfies and full transaction histories to a malicious actor.
— International Cyber Digest (@IntCyberDigest) September 12, 2026
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later… pic.twitter.com/QFlIlUFpxH
Revolut, however, did not specify how many people were affected. It also did not reveal if the security breach occurred within a particular market alone and did not disclose which government body was involved. “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.
According to the report from TechCrunch, Revolut blocked the email address after realising the scam carried out by the unauthorised third party and notified the appropriate government agency, law enforcement, and regulators, saying that “Revolut systems and customer funds are unaffected.” The incident created a buzz on X, with people criticising the existing practice of mandated information sharing. Marc Zeller posted that he woke up to Revolut leaking all his data. He added, “A sharp reminder that KYC has not delivered any upside, but rather gotten us into trouble.”
In a similar incident in August, Bits of Gold, a cryptocurrency brokerage service, revealed that cybercriminals hacked about 200,000 users' personal information. They disclosed the data breach incident on Sunday, stating that one hacker managed to gain entry into a third-party data analytics system, thereby gaining access to customers' names, national IDs, email addresses, phone numbers, IP addresses, bank details, and public wallet addresses.
Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.
Samsung Galaxy Watch 9 (44mm, LTE)
Starts from ₹44,590
Samsung Galaxy Watch 9 (40mm, LTE)
Starts from ₹41,061
Samsung Galaxy Watch 9 (40mm)
Starts from ₹37,999
Haier M70 Mini LED 65-inch
Starts from ₹74,990
CMF Buds Neo True Wireless Stereo (TWS) Earphones
Starts from ₹2,199
Xiaomi TV FX Mini LED 65
Starts from ₹64,999