Cybersecurity

Revolut Data Breach Exposes Passports After Fake Government Requests

By Nino Ray Yeh · September 13, 2026 · 7:48 am AEST · 4 min read
Smartphone representing the Revolut customer data breach and fake government information requests

A data breach at Revolut did not begin with hackers forcing their way through the digital bank’s systems. Instead, the company says an unauthorised third party convinced it to hand over sensitive customer information by sending fraudulent requests from what appeared to be a trusted government channel.

Revolut confirmed on September 12 that a limited number of customers were affected by what it described as a sophisticated external impersonation scam. The requests came from an email address using a legitimate government agency domain, according to statements provided to Reuters and TechCrunch.

That distinction makes this incident particularly uncomfortable for the wider technology and financial industries. The attackers apparently did not need to defeat Revolut’s banking infrastructure. They exploited the process used to decide when sensitive information should be released.

What happened in the Revolut data breach?

Revolut told Reuters that it disclosed customer information to an unauthorised third party after receiving fraudulent information requests from a legitimate government agency email domain.

The company has not publicly identified the agency involved or disclosed exactly how many customers were affected.

A notification sent to affected customers and reviewed by TechCrunch gives a clearer picture of the information at risk. It included identity and contact information such as dates of birth, postal addresses, email addresses and phone numbers. Copies of identity documents including passports and driver licences were also among the exposed information.

Depending on the customer, the disclosure may also have included verification selfies, account statements and transaction histories.

Revolut says its systems and customer funds were not affected. After identifying the fraudulent requests, the company says it blocked the email address and contacted the relevant government agency, law enforcement, data-protection authorities and financial regulators.

This was not a conventional bank hack

The most important part of the story is how the information appears to have been obtained.

Cybersecurity is often discussed in terms of malware, stolen passwords, software vulnerabilities and attackers breaking into servers. Those threats remain very real. But organisations also have processes that allow sensitive information to leave otherwise secure systems for legitimate reasons — including requests from governments and law-enforcement agencies.

If an attacker can convincingly impersonate one of those trusted parties, the security problem shifts from protecting a database to verifying who is asking for the information.

That is why the Revolut incident has implications well beyond one fintech company. Banks, telecommunications providers, cloud platforms and technology companies routinely receive lawful requests for customer information. The integrity of the verification process surrounding those requests can be just as important as the encryption protecting the underlying data.

It also fits a broader pattern we have been following at The Tech Boom: attackers increasingly look for ways around security controls rather than confronting them directly. Microsoft recently warned about phishing campaigns using invisible Unicode characters to disguise malicious messages, another example of attackers manipulating trust and interpretation instead of relying only on technical exploits.

What should Revolut customers do?

Revolut says it has contacted the customers known to have been affected. If you have not received a notification, there is currently no evidence from the company that every Revolut customer was exposed.

For anyone who does receive a breach notice, however, the nature of the information matters. A password can be changed. A passport number, date of birth, address and identity photograph are much harder to replace and can potentially make later impersonation attempts more convincing.

Affected customers should be particularly cautious about unexpected emails, text messages or calls claiming to come from Revolut, a government agency or another financial institution. Someone possessing genuine personal information can use those details to make a fraudulent approach appear legitimate.

Customers should access Revolut through the official app or website rather than links contained in unexpected messages, use the account security options available to them and carefully review transactions and account activity.

Revolut’s Australian privacy policy says the company collects a wide range of information for identity verification and financial services, including identification documents, account details and transaction information. That illustrates why verification around requests for this type of data is so consequential.

The bigger cybersecurity lesson

The breach arrives as cyber threats themselves are becoming more automated. Google recently warned that attackers are beginning to move toward agentic AI workflows capable of assisting with scanning and credential theft. Yet the Revolut incident is a reminder that sophisticated attacks do not always require sophisticated code.

A trusted email domain and a convincing request can sometimes be enough if the process behind the security boundary fails.

The unanswered question is therefore not simply how Revolut protects its servers. It is how a fraudulent request passed the checks used before sensitive customer records were released — and what changes will now be made to stop the same technique from working again.

Revolut has said the affected group was limited, but it has not disclosed a number or identified the government agency whose domain was used. Those details will matter as regulators and customers assess the scale of the incident.

Featured image: Dan Nelson via Unsplash.

Share this story

Topics

More From The Tech Boom

View all

Share with