Revolut Confirms Data Breach After Attackers Impersonated Government Authorities
Revolut has disclosed that customer passport documents and cryptocurrency activity records were handed to attackers who successfully impersonated state authorities, exploiting the neobank's own compliance processes in a sophisticated social-engineering attack disclosed on 12 September 2026.

The breach demonstrates that compliance infrastructure built to satisfy legal obligations can itself become an attack surface, posing a systemic risk question for every regulated financial institution that routinely processes government data requests.
Revolut Discloses Data Breach Triggered by Fake Government Requests
Revolut, the London-headquartered neobank and one of Europe's most valuable fintech companies, has confirmed that customer data — including identity documents and cryptocurrency activity records — was exposed after attackers successfully impersonated government authorities to extract sensitive information from the company.
The incident, disclosed on 12 September 2026, represents one of the more sophisticated social-engineering attacks to strike a major European fintech in recent memory. Rather than exploiting a technical vulnerability in Revolut's systems, the perpetrators appear to have manipulated the company's own compliance processes — the very procedures designed to ensure lawful cooperation with legitimate state authorities.
What Happened: Social Engineering Through Regulatory Mimicry
At its core, the breach exploited a process that financial institutions handle routinely: responding to formal government data requests. Banks and regulated payment firms receive such demands regularly from law enforcement and judicial authorities, and they are legally obligated to respond promptly. That obligation creates a structural pressure that attackers in this case turned into a weapon.
According to reporting by TechCraft and Reuters, Revolut handed over customer passport data and records of Bitcoin activity after receiving requests that appeared to originate from a government agency but were, in fact, fraudulent. The company said it notified affected customers after discovering the requests were fake.
The incident is a reminder that compliance infrastructure — built to serve the law — can itself become an attack surface when adversaries learn to mimic the shape of legitimate authority.
The precise mechanism by which the fake requests were submitted, and how they passed Revolut's internal verification, has not been publicly detailed by the company. The number of customers affected has also not been confirmed in sources independently reviewed by Fin Desk.
Passport and Bitcoin Data: A Sensitive Combination
What makes this breach particularly consequential is the nature of the data involved. Passport documents are primary identity credentials; in the wrong hands they can underpin identity fraud, account takeovers and, in more serious cases, facilitate travel document forgery. When combined with records of a customer's Bitcoin activity — which can reveal transaction patterns, wallet behaviour and financial habits — the exposure creates a profile that is both financially and personally sensitive.
For Revolut's customer base, which spans tens of millions of retail and business users across Europe and beyond, the breach raises questions about how the company verifies the authenticity of government data requests and whether its processes are calibrated for an era in which state-impersonation attacks are an established threat vector.
It is important to note that Revolut's public characterisation of the event — that the requests were fake and that the company was deceived — represents the company's own account. Independent verification of the full chain of events, including how the fraudulent requests were constructed and submitted, has not been possible from publicly available sources at the time of publication.
Regulatory and Reputational Stakes
Revolut operates under a UK banking licence granted by the Prudential Regulation Authority and is regulated across multiple European jurisdictions. Data protection obligations under the UK GDPR and, where applicable, the EU GDPR require firms to notify regulators of personal data breaches within 72 hours of becoming aware of them, where the breach is likely to result in a risk to individuals' rights and freedoms.
The disclosure arrives at a sensitive moment for Revolut. The company has spent years building institutional credibility to support its banking licence ambitions and international expansion. A breach of this nature — one that implicates not just cybersecurity defences but the integrity of compliance workflows — is the kind of incident that regulators scrutinise carefully, not only for its immediate impact but for what it reveals about a firm's governance and operational controls.
A Broader Industry Warning
From a sector-wide perspective, this incident should prompt compliance and security teams across regulated financial services to revisit their procedures for authenticating inbound government data requests. The financial industry's legal duty to cooperate with authorities is precisely the leverage attackers exploited here, and Revolut is unlikely to be the only institution whose processes could be tested in this way.
Verification protocols — such as independently confirming requests through official government contact channels rather than those supplied in the request itself — are standard best practice, but their rigour varies considerably across institutions of different sizes and regulatory maturities.
Fin Desk will update this article as further verified details become available, including any regulatory response or official statement from Revolut beyond the customer notifications reported so far.
Fin Desk contacted Revolut for comment. No response had been received at the time of publication.
The Fin Desk Newsroom publishes verified reporting on the developments shaping fintech, payments and modern financial infrastructure.
Related Stories

Italy's Biorsaf Raises €5.2M Series A and Acquires Bologna's Cooki in Food RegTech Push
Tuscany-based Biorsaf has secured a €5.2 million Series A led by P101 SGR and acquired Bologna platform Cooki, positioning the combined business as Italy's first end-to-end food RegTech operator. The deal targets a domestic food safety and compliance market generating more than €12 billion in annual revenue but with a digitisation rate of approximately 3%.
The essential developments in modern finance
The essential developments across fintech, payments and modern finance — delivered to your inbox.
Free. No spam. Unsubscribe anytime.