SciVersum

Revolut Data Leak Exposes Sensitive Customer Information

Fraudulent Email from Government Domain Raises Security Concerns for Fintech

Category: Business

In a troubling incident for the fintech industry, British financial technology company Revolut has confirmed a data leak that exposed sensitive customer information, including identity documents and banking records. The breach, flagged on September 12, 2026, by on-chain investigator ZachXBT, was triggered by a fraudulent email that appeared to come from a legitimate government agency, raising serious questions about how financial firms verify official requests.

The fraudulent email carried valid domain authentication credentials, which enabled it to pass security checks that are typically in place to confirm the legitimacy of such requests. As a result, Revolut mistakenly believed the request was genuine and disclosed a wealth of sensitive data to unauthorized parties.

What Happened

The incident was first reported by ZachXBT, who shared a customer notification from Revolut detailing the breach. According to the notification, the company received a request for customer information that appeared to originate from a legitimate government agency. The request was sent from an unauthorized email account using the agency's actual domain, which allowed it to pass the necessary authentication checks. "As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request," Revolut stated.

The Science Behind It

What makes this case particularly alarming is the method used by the attackers. Instead of employing common phishing tactics, they exploited trust in official channels by sending the request from an account within the legitimate government agency's domain infrastructure. This sophisticated impersonation scheme raises concerns about the effectiveness of email authentication systems used by financial institutions. Revolut emphasized that no systems were breached or hacked; rather, it was a failure to verify the legitimacy of the request.

What They Found

The data that was leaked includes a range of sensitive information. According to the company, the exposed data comprised full names, dates of birth, occupations, postal addresses, email addresses, telephone numbers, and copies of identity documents such as passports and driver's licenses. In addition, verification selfies submitted during the onboarding process, IBANs, account-opening dates, Bitcoin wallet reference numbers, withdrawal records, and complete transaction histories were also disclosed. Notably, Revolut clarified that no biometric facial telemetry data was involved in the leak.

Impact and Scope of the Security Breach

So far, the fallout from the breach appears to be limited in scale, but the implications could be severe. ZachXBT noted that the incident may have targeted high-net-worth individuals, as the combination of identity documents and transaction histories provides a detailed profile that could be exploited for fraud or identity theft. Some affected users have already received notification emails from Revolut confirming the disclosure.

Revolut operates on a massive scale, serving over 80 million customers worldwide. The company has been actively pushing into new markets, recently launching a euro-backed stablecoin and obtaining conditional approval for a national bank in the U.S. Yet, the timing of this incident is particularly unfortunate as it raises questions about the company's ability to safeguard sensitive financial data.

Why It Matters

The potential risks to affected users extend beyond the immediate exposure of their data. When identity documents and transaction records are leaked, it creates a treasure trove for fraudsters, allowing them to engage in identity theft or highly personalized phishing attacks. This incident highlights a broader vulnerability across the fintech sector: the reliance on institutional trust when responding to data requests. Any platform that processes law enforcement or regulatory requests could face similar challenges if it cannot independently verify the authenticity of the request.

What to Watch

In response to the breach, Revolut has taken steps to mitigate the damage. The company has blocked the fraudulent email address used in the attack, alerted the government agency involved, notified law enforcement, and reported the incident to financial regulators. Revolut has not disclosed the exact number of affected customers or identified the government agency involved, citing concerns that naming the agency could allow other firms to check their own request logs for similar communications.

As the company continues to expand its banking operations globally, including plans to launch a national bank in the U.S. in 2027, the need for enhanced verification processes becomes increasingly urgent. The incident serves as a reminder that even established fintech firms are not immune to sophisticated impersonation attacks.

Timeline of Events

  • September 11, 2026: Revolut begins notifying affected customers about the data breach.
  • September 12, 2026: ZachXBT flags the data leak on social media, highlighting the fraudulent nature of the request.
  • September 12, 2026: Revolut confirms the breach and details the types of data that were exposed.
  • September 12, 2026: Revolut blocks the fraudulent email address and reports the incident to law enforcement and regulators.

This breach raises questions about the integrity of data request processes in the fintech sector. As the industry continues to evolve, the need for improved verification mechanisms will be a key focus for companies looking to protect sensitive user information.