Skip to content
feed: live
>_0dayNews
threat intel
● Breaking

Revolut Breach Exposes Passports and Financial Data

A threat actor impersonated a government agency to obtain passport copies, identity documents, and complete transaction records from an undisclosed number of Revolut customers.

Revolut Breach Exposes Passports and Financial Data
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Breach confirmed. Revolut disclosed on September 14, 2026 that a threat actor impersonating a government agency obtained sensitive customer data. The attack vector: email from a valid official government domain. Revolut fulfilled the request believing it was legitimate.

Data exposed

Per Revolut’s disclosure:

  • Full name, date of birth, occupation
  • Postal address, email address, phone number
  • Passport and driver’s license copies from KYC verification
  • Facial verification selfies
  • Account IBAN numbers
  • Complete transaction history, including Bitcoin transactions

Scope

Number of affected customers: not disclosed. Revolut characterizes the exposure as “very limited.” Crypto investigator ZachXBT assessed the campaign as targeted at high net worth users. Confidence on that characterization: unconfirmed, treat accordingly.

Revolut’s statement

“Revolut systems and customer funds are unaffected. Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”

The full customer funds caveat applies narrowly: account balances were not taken. Identity documents and transaction history were.

Attack vector

No technical vulnerability involved. The threat actor sent email from an official government domain with valid authentication credentials, impersonating an agency making a data request. Revolut’s internal process honored it. Operational exposure, not a patching problem.

Prior record

Revolut disclosed a separate breach in September 2022 affecting 50,150 customers. That incident involved unauthorized access to internal systems via a phishing attack. This incident is distinct: the company itself was the access point, not a system compromise.

Revolut serves approximately 80 million customers across 160 countries. Per-account KYC data at this scale includes government identity document scans and full transaction records: the kind of data that enables identity fraud and targeted financial attacks regardless of how few accounts were breached.


Related: BioStar 2 API was leaking Active Directory credentials in a separate disclosure today. OAuth token theft via open redirect was documented yesterday.

Found this useful? Share it.