
On Saturday, September 12, 2026, Glitchwire reported that Revolut, a prominent digital bank, disclosed sensitive customer information to an unauthorized third party after falling victim to a sophisticated phishing attack.
The fraudulent request, which appeared to originate from an official government agency’s domain and passed all authentication checks, led Revolut to hand over personal data, including passports, driver’s licenses, and Bitcoin transaction histories.
The incident, described by Revolut as a “sophisticated external impersonation attack,” involved an email that was indistinguishable from a legitimate government communication. This email requested customer files and, due to its convincing nature, Revolut complied. The disclosed data encompassed copies of identity documents, selfies submitted for verification, account statements with details like IBANs and account-opening dates, and specific Bitcoin wallet reference numbers along with full transaction histories.
Revolut has clarified that no login credentials, passwords, or account access were compromised, and customer funds remain unaffected.
However, for individuals whose identity documents and financial records were both exposed, the recipient now possesses a detailed financial profile linked to a verified real-world identity. This combination of information can be exploited for targeted phishing, fraudulent account creation, and, in more severe instances, physical threats against cryptocurrency holders.
This type of social engineering attack is not new. As early as 2022, security researchers documented similar tactics where attackers spoofed emergency data requests to obtain customer information from service providers. Proposals to mitigate such attacks, like requiring digital signatures on government requests, have not been widely implemented and may not fully address issues arising from compromised accounts operating within legitimate government infrastructure.
The article notes that financial institutions constantly receive government data requests, including law enforcement inquiries and court orders, and are built to comply with them when properly verified. The Revolut incident is characterized as a failure of this verification layer rather than a technical breach, as no malware was involved and no credentials were stolen.
Revolut has not disclosed the exact number of customers affected or the specific government agency whose domain was impersonated. However, initial indications suggest that a small subset of users, likely high-net-worth individuals, were targeted. Customers received notification emails regarding the breach on September 11.
In response, Revolut has blocked the unauthorized email address across its systems, notified relevant regulators, and implemented precautionary protection measures for affected customers. The company has also alerted the impersonated government agency.
Revolut serves over 70 million customers globally as of January 2026, making it the largest digital bank in Europe.
For affected customers, the advice provided is to treat any unexpected communication referencing the leak as high risk, as the exposed records contain details that attackers could use to impersonate customer service, initiate account recovery, or construct pretexts for further fraud. The article emphasizes that while you can change a password, you can’t change a passport.
Source: Glitchwire





Be the first to comment