Revolut Confirms Data Breach After Handing Customer Info to Impostors
- Fintech giant Revolut accidentally handed sensitive customer documents—including passport scans and cryptocurrency transaction histories—to cybercriminals operating a real government email domain.
- Reporting from TechCrunch and on-chain intelligence shared by crypto researcher ZachXBT on September 12, 2026, confirmed that Revolut systems were never directly compromised during the incident.
- Details highlighted in coverage from Euro Weekly News show that the compromised data bundles contained a wide range of personal information.
Fintech giant Revolut accidentally handed sensitive customer documents—including passport scans and cryptocurrency transaction histories—to cybercriminals operating a real government email domain. Reports published on September 12, 2026, reveal the breach occurred because company support staff mistook the fraudulent data request for an authentic official inquiry after it successfully passed standard email security checks.
Revolut Handed Sensitive Customer Files to Cybercriminals via Phishing Scheme
Reporting from TechCrunch and on-chain intelligence shared by crypto researcher ZachXBT on September 12, 2026, confirmed that Revolut systems were never directly compromised during the incident. A Revolut spokesperson confirmed to TechCrunch that the company’s internal networks remained untouched and that no funds were stolen from accounts. Passcodes and login credentials were also excluded from the leaked file packages.
The Scale of the Identity and Financial Data Leak
Details highlighted in coverage from Euro Weekly News show that the compromised data bundles contained a wide range of personal information. The files given to the impostors included copies of passports or driving licences, alongside the original selfie photos provided by users during identity verification checks. Biometric facial templates were not included in the leak, only the raw image stills.
Additional records in the leaked packages exposed full names, dates of birth, home addresses, personal email addresses, phone numbers, and user occupations. Financial data was also compromised. According to reports, account statements detailing IBANs, account opening dates, transaction withdrawals, and full payment trails including Bitcoin records were handed over to the unauthorized mailbox.
Immediate Containment Measures and Regulatory Reporting
Revolut officials stated that once the unauthorized nature of the mailbox was discovered, the address was blocked immediately. The company reported the security incident to the relevant government agency, local police forces, and regulatory authorities. While the exact number of affected individuals has not yet been officially disclosed, investigator ZachXBT noted that the targeted group appears relatively small and heavily tilted toward high-net-worth users.
Secondary Fraud Risks Facing Affected Users
Fraudsters can potentially leverage this specific combination of documents to open unauthorized financial accounts, apply for credit lines, or execute SIM-swap attacks to intercept future text-based authentication codes.

