Breaking
Cyber CrimeConfirmed

Revolut breach spotlights ID verification gaps

A fintech breach via fake government emails exposes sensitive customer data, raising questions about verification controls.

··2 hours ago·5 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

When a message arrives from what appears to be a legitimate government agency, employees at regulated financial institutions are trained to treat it as a legal compliance matter, not a threat. That assumption is now at the center of a data breach at Revolut, the British fintech firm, which has confirmed that an unauthorized third party used a fake government domain to obtain sensitive customer information.

The incident, reported by Infosecurity Magazine on September 14, 2026, involved fraudulent requests for information sent using a "legitimate government agency domain email." According to a Revolut spokesperson, the requests carried valid technical domain authentication and were fulfilled by employees as standard legal compliance. The company described the technique as a "sophisticated external impersonation scam" that led it to disclose sensitive information to the threat actor.

The mechanics of the impersonation scam

At the heart of the breach is a simple but effective deception: attackers sent emails that appeared to originate from a real government agency domain. Because the messages passed technical domain authentication checks, they looked legitimate to the employees who processed them. Those employees, following standard procedures for legal compliance requests, handed over customer data.

Revolut said its security team "immediately blocked the address" upon detection, notified affected customers, and alerted the relevant government agency as well as enforcement agencies, data protection and financial regulators. The company also stated that only a "very limited group of customers" were affected and that its systems and customer funds were untouched.

However, Revolut declined to comment further on the number of affected customers or whether the breach affected any specific market or department. That lack of detail leaves key questions unanswered about the scope of the incident.

What data was exposed

On September 12, independent crypto-security researcher ZachXBT issued a warning about the breach via a post on Telegram, sharing a customer notification sent out by Revolut the previous day and disclosing that sensitive user records had been improperly accessed.

The compromised data reportedly includes full names, dates of birth, residential addresses, phone numbers, email addresses and occupations, along with copies of government ID documents such as passports and driver's licenses, and verification selfies.

Additionally, ZachXBT claimed that financial information was exposed, including IBANs, account-opening dates, complete transaction and withdrawal histories and Bitcoin wallet reference numbers.

For a financial institution that relies on digital identity verification, the exposure of that combination of data is particularly serious. It provides attackers with a ready-made toolkit for impersonation and fraud.

Experts question verification controls

The breach has drawn sharp criticism from security professionals who question how a regulated fintech could be tricked by a fake government request. Muhammad Yahya Patel, vCISO & cybersecurity advisor at Huntress, noted: "For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high. The question is: why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it."

"For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high. The question is: why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it."

— Muhammad Yahya Patel, vCISO & cybersecurity advisor at Huntress

Patel's point cuts to a broader issue: even when technical authentication checks pass, organizations must verify the legitimacy of the request itself, especially when it involves sensitive customer data.

A complete identity theft kit

Jamie Akhtar, CEO and co-founder of CyberSmart, cautioned that although Revolut said customer funds and its systems were unaffected, the exposed information could still be exploited for identity fraud and highly targeted phishing attacks.

Huntress' Patel also warned that the range of data that could be compromised for affected customers "go well beyond a standard data breach notification."

"Passports, driver's licenses, verification selfies, account statements, transaction histories, birth dates, addresses… that's not a data leak, that's a complete identity theft kit handed to whoever sent those fraudulent requests."

— Muhammad Yahya Patel, vCISO & cybersecurity advisor at Huntress

That assessment underscores the severity of the exposure: the stolen data can be used to open new accounts, bypass identity checks, or craft convincing phishing messages that reference real personal details.

What affected customers should do now

Akhtar offered direct advice for those whose data may have been compromised. "Affected customers should be particularly cautious of unexpected calls, emails or messages claiming to come from Revolut, government bodies or other trusted organizations," he advised.

He also said: "They should never disclose passwords, passcodes or one-time security codes, and should contact Revolut only through its official app or verified website."

Beyond that, Akhtar recommended that users of any digital financial services, even those unaffected by this breach, enable multi-factor authentication (MFA), use unique passwords, monitor accounts and credit reports for unusual activity and report suspected identity misuse promptly.

The verification gap in financial services

The Revolut breach highlights a specific vulnerability: the trust placed in government-domain emails. Attackers exploited that trust by sending requests that appeared technically valid. For financial institutions, the challenge is to balance compliance with legal requests against the need to verify the requester's authenticity.

Revolut's response—blocking the address, notifying customers and regulators—follows standard incident response, but the incident raises questions about whether current verification processes are sufficient. As Patel's comments suggest, the bar for verifying third-party data requests should be higher, particularly when the request involves sensitive personal data.

The company has not disclosed how many customers were affected or which markets were impacted. That lack of transparency may complicate efforts to assess the full impact and could leave affected customers uncertain about their exposure.

Why this matters beyond Revolut

For businesses, the incident is a reminder that technical authentication alone does not guarantee a request is legitimate. Social engineering attacks that exploit trusted domains can bypass traditional security controls, especially when employees are following standard procedures.

For consumers, the breach is a warning about the value of their personal data. The combination of identity documents, financial details and contact information creates a comprehensive profile that can be used for fraud. Even if funds are not directly stolen, the long-term risks of identity theft can be significant.

The incident also raises questions about regulatory oversight. Financial regulators may need to examine whether current rules adequately address impersonation attacks that use legitimate domains. As digital finance grows, the methods used by attackers will likely evolve, and institutions will need to adapt their verification processes accordingly.

For now, Revolut customers should remain vigilant. The company has notified those affected and alerted authorities. But the breach serves as a case study in how a well-crafted impersonation can penetrate even sophisticated defenses, and why verification must go beyond checking a domain's technical validity.

#revolut#data breach#fintech#identity theft#social engineering

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories