Revolut has disclosed a data breach that exposed customer financial details and passport information after staff handed the data to a threat actor posing as a government agency.
Revolut operates as a banking and payments app that holds financial account details, transaction histories, and the identity documents customers submit during account verification. That is what makes it a target for impersonation attempts: a single successful request can return far more than a login credential, it can return a customer’s full financial and identity profile in one file.
How the Revolut data breach happened
The company has not said how many customers were affected or over what period the exposure took place. What it has confirmed is the mechanism: this was not a network intrusion. Someone contacted Revolut claiming to represent a government body, and staff released customer records in response to that request.
Those records reportedly included passport images and financial account details, according to BleepingComputer, which was first to report the disclosure. That framing matters: a request that should have been verified against a known government channel was not, and records moved before anyone caught the impersonation.
The tactic is a form of pretexting: attackers request data under the appearance of legal authority, sometimes with a document or reference number that is convincing enough to pass a first review, and staff release records without an independent verification step such as calling the agency back on a number pulled from its own published contact details rather than one supplied by the requester.
For a company that presents itself as digital-first and largely automated, the incident is a reminder that identity verification requests still pass through people, and people can be misled by a document or a call that looks official enough. Revolut has not published its own breach notice with a total count of affected customers, nor said whether it has reported the incident to the UK Information Commissioner’s Office.
A pattern of third-party data exposure
Teqpost has covered a similar failure before: the Revolut data breach follows Grindr’s £26 million settlement, reported on 9 September 2026, after UK regulators found the company had shared users’ HIV status with advertising and analytics partners. The mechanism differs: Grindr’s sharing was built into how it routed data to partners over time, while Revolut’s appears to be a single deception aimed at extracting one batch of records. The result sits in the same category of harm, sensitive data ending up somewhere the company did not intend and cannot recall. Read our coverage of the Grindr HIV status data sharing settlement for how that case was resolved.
What to watch next
Revolut has not said whether it has notified affected customers individually. Data breaches involving passport-grade identity documents typically trigger notification obligations to national data protection authorities, and in the UK that means the ICO. Passport images and financial account details are enough to support identity theft and account takeover attempts, so anyone who banks with Revolut should treat unexpected verification requests, especially ones citing this breach, with the same scepticism the company itself failed to apply the first time.








