
Passports and ID Copies Exposed After Revolut Falls for Email Scam
British fintech Revolut confirmed a sensitive customer data breach on September 12, 2026, after falling for fraudulent requests sent from a legitimate government agency email domain. Account holders faced exposure of personal identity records after an unauthorized third party exploited the official communication channel.
Stolen Identity Files Include Passports and Driver’s Licences While Account Funds Remain Secure
Exposed records contain customer birth dates, postal addresses, email addresses, phone numbers, and copies of identity documents including passports and driver’s licences. The company blocked the compromised email address immediately upon detection and notified the targeted government agency, law enforcement, data protection authorities, and financial regulators. Revolut confirmed that its core operating systems and customer balances remained unaffected, though the firm has not disclosed the total number of individuals impacted by the breach.
The security incident comes as the branchless European fintech prepares for a potential public listing aimed at reaching a $200 billion valuation.



