Revolut Confirms Data Breach After Attackers Impersonated Government Authorities
Revolut has disclosed that customer passport documents and cryptocurrency activity records were handed to attackers who successfully impersonated state authorities, exploiting the neobank's own compliance processes in a sophisticated social-engineering attack disclosed on 12 September 2026.

The breach demonstrates that compliance infrastructure built to satisfy legal obligations can itself become an attack surface, posing a systemic risk question for every regulated financial institution that routinely processes government data requests.
Revolut Discloses Data Breach Triggered by Fake Government Requests
Revolut, the London-headquartered neobank and one of Europe's most valuable fintech companies, has confirmed that customer data — including identity documents and cryptocurrency activity records — was exposed after attackers successfully impersonated government authorities to extract sensitive information from the company.
The incident, disclosed on 12 September 2026, represents one of the more sophisticated social-engineering attacks to strike a major European fintech in recent memory. Rather than exploiting a technical vulnerability in Revolut's systems, the perpetrators appear to have manipulated the company's own compliance processes — the very procedures designed to ensure lawful cooperation with legitimate state authorities.
What Happened: Social Engineering Through Regulatory Mimicry
At its core, the breach exploited a process that financial institutions handle routinely: responding to formal government data requests. Banks and regulated payment firms receive such demands regularly from law enforcement and judicial authorities, and they are legally obligated to respond promptly. That obligation creates a structural pressure that attackers in this case turned into a weapon.
According to reporting by TechCraft and Reuters, Revolut handed over customer passport data and records of Bitcoin activity after receiving requests that appeared to originate from a government agency but were, in fact, fraudulent. The company said it notified affected customers after discovering the requests were fake.
The incident is a reminder that compliance infrastructure — built to serve the law — can itself become an attack surface when adversaries learn to mimic the shape of legitimate authority.
The precise mechanism by which the fake requests were submitted, and how they passed Revolut's internal verification, has not been publicly detailed by the company. The number of customers affected has also not been confirmed in sources independently reviewed by Fin Desk.
Passport and Bitcoin Data: A Sensitive Combination
What makes this breach particularly consequential is the nature of the data involved. Passport documents are primary identity credentials; in the wrong hands they can underpin identity fraud, account takeovers and, in more serious cases, facilitate travel document forgery. When combined with records of a customer's Bitcoin activity — which can reveal transaction patterns, wallet behaviour and financial habits — the exposure creates a profile that is both financially and personally sensitive.
For Revolut's customer base, which spans tens of millions of retail and business users across Europe and beyond, the breach raises questions about how the company verifies the authenticity of government data requests and whether its processes are calibrated for an era in which state-impersonation attacks are an established threat vector.
It is important to note that Revolut's public characterisation of the event — that the requests were fake and that the company was deceived — represents the company's own account. Independent verification of the full chain of events, including how the fraudulent requests were constructed and submitted, has not been possible from publicly available sources at the time of publication.
Regulatory and Reputational Stakes
Revolut operates under a UK banking licence granted by the Prudential Regulation Authority and is regulated across multiple European jurisdictions. Data protection obligations under the UK GDPR and, where applicable, the EU GDPR require firms to notify regulators of personal data breaches within 72 hours of becoming aware of them, where the breach is likely to result in a risk to individuals' rights and freedoms.
The disclosure arrives at a sensitive moment for Revolut. The company has spent years building institutional credibility to support its banking licence ambitions and international expansion. A breach of this nature — one that implicates not just cybersecurity defences but the integrity of compliance workflows — is the kind of incident that regulators scrutinise carefully, not only for its immediate impact but for what it reveals about a firm's governance and operational controls.
A Broader Industry Warning
From a sector-wide perspective, this incident should prompt compliance and security teams across regulated financial services to revisit their procedures for authenticating inbound government data requests. The financial industry's legal duty to cooperate with authorities is precisely the leverage attackers exploited here, and Revolut is unlikely to be the only institution whose processes could be tested in this way.
Verification protocols — such as independently confirming requests through official government contact channels rather than those supplied in the request itself — are standard best practice, but their rigour varies considerably across institutions of different sizes and regulatory maturities.
Fin Desk will update this article as further verified details become available, including any regulatory response or official statement from Revolut beyond the customer notifications reported so far.
Fin Desk contacted Revolut for comment. No response had been received at the time of publication.
The Fin Desk Newsroom publishes verified reporting on the developments shaping fintech, payments and modern financial infrastructure.
Related Stories

US Treasury and Education Dept launch Defaulted Loans Support Center portal
The US Treasury Department and Department of Education jointly announced the Defaulted Loans Support Center on 30 September 2026, a digital portal aimed at helping Americans with defaulted federal student loans understand their options and return to repayment.

Circle Internet Group CFO Jeremy Fox-Geen to Step Down in Leadership Transition
Circle Internet Group announced on 25 September 2026 that CFO Jeremy Fox-Geen will step down, with no successor confirmed. The disclosure follows the stablecoin issuer's submission of a 424B4 final prospectus in June 2025.

SBI Group Takes Stake in Singapore Stablecoin Payments Firm dtcpay
Japan's SBI Group has joined a US$25 million Series A for Singapore's dtcpay, a Monetary Authority of Singapore-licensed stablecoin payments platform — a deal that signals institutional capital is treating regulated digital-asset settlement infrastructure as a mature asset class.

Ant International Bets on AI-Native Stack to Rewire Cross-Border Commerce Infrastructure
Ant International has unveiled a broad AI-native product suite spanning payments, treasury, FX and growth marketing under its Antom brand, positioning itself as a unified financial technology layer for cross-border enterprise commerce. The move intensifies competition with point-solution vendors but faces geopolitical headwinds and enterprise consolidation inertia.
The essential developments in modern finance
The essential developments across fintech, payments and modern finance — delivered to your inbox.
Free. No spam. Unsubscribe anytime.