Revolut confirmed on September 12, 2026 that it handed sensitive customer records to an impostor who submitted fraudulent information requests from a real government agency's email domain. Exposed data included dates of birth, addresses, phone numbers and copies of passports and driver's licenses. Your funds were not touched — your identity documents were.
What Actually Happened
This was not a hack. Nobody broke into Revolut's systems, and the company has been clear that customer funds and account infrastructure were never compromised. What happened is arguably worse for the people affected: an unauthorized third party sent Revolut what looked like a legitimate law-enforcement or regulatory request for customer information, from an email address on a genuine government agency domain. Revolut's review process passed it, and the data went out.
Revolut described it as "a sophisticated external impersonation scam." Once detected, the company blocked the sending address, notified the government agency whose domain was abused, and alerted law enforcement, data protection regulators and financial regulators. Affected customers were contacted directly.
Why This Breach Is Different
Most breaches leak email addresses and hashed passwords, which you fix by changing a password. This one leaked identity documents — passport and driver's license images, verification selfies, and in some cases account statements and transaction histories. You cannot rotate a passport number the way you rotate a password, which is why the response below focuses on identity monitoring rather than credentials.
Who Was Affected and What Was Exposed
Revolut says only a "very limited group of customers" was affected and has not published a number. Reporting on the incident suggests the requests were targeted rather than bulk — aimed at specific, often high-net-worth account holders rather than scraping the whole customer base. That is consistent with how fraudulent-request abuse usually works: the attacker asks for named individuals.
Data that may have been disclosed for affected customers:
- Identity details: full name, date of birth
- Contact details: postal address, email address, phone number
- Identity documents: copies of passports and driver's licenses
- Verification media: selfies submitted during KYC onboarding
- Financial records: account statements and transaction histories, including cryptocurrency transaction history in some reported cases
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 1: Confirm Whether You Were Notified — Inside the App
Revolut contacted affected customers directly. Do not judge this from your inbox alone: a breach with this much profile attracts fake "Revolut security alert" emails within days. Open the Revolut app yourself and check your in-app messages and notifications. If something arrives by email claiming to be Revolut, do not click the links — go to the app and verify there.
Step 2: Audit Your Revolut Account
Whether or not you were notified, spend ten minutes on this:
- Review recent transactions, transfers and card payments for anything unfamiliar
- Check your saved beneficiaries and delete any you do not recognize
- Review linked devices and active sessions, and remove old ones
- Confirm your registered email and phone number have not been changed
- Report anything unexpected through Revolut's secure in-app chat, not by phone or email
Step 3: Treat Your ID Documents as Compromised
If your passport or driver's license image was disclosed, assume it can be used to open accounts, pass weak identity checks, or build a convincing synthetic identity. Practical steps:
- Report the exposure to your passport issuing authority and ask what they recommend — some jurisdictions will flag or reissue
- Ask your state DMV (or national equivalent) about a replacement license number if your jurisdiction allows it
- Keep a dated record of the breach notification; you will need it if you later dispute a fraudulent account
Step 4: Freeze Your Credit
A credit freeze is free, reversible, and the single most effective control against someone opening credit in your name. In the US, freeze with all three bureaus — Equifax, Experian and TransUnion — plus Innovis and the NCTUE. In the UK and EU, register with CIFAS-style protective registration or the equivalent fraud-prevention service in your country.
Step 5: Expect Targeted Impersonation Attempts
Whoever holds your date of birth, address and passport image can construct an extremely convincing approach — a "bank security team" call that already knows your details, or a request to verify a transfer. Adopt one rule: you never confirm identity to someone who contacted you. Hang up, open the app, and use in-app chat. Legitimate financial institutions never lose anything when you do that.
Step 6: Harden the Account Itself
Set a unique passcode and password not used anywhere else, enable biometric unlock, and move off SMS-based codes to an authenticator app or passkey where Revolut supports it. If you reused your Revolut password on any other site, change it there too.
Step 7: Reduce the Data That Makes You a Target
Fraudulent-request scams need a name to ask about. Attackers build target lists from people-search sites and data brokers that publish your address history, phone numbers, age, relatives and rough net-worth signals for a few dollars. Removing those listings does not undo this breach, but it makes you materially harder to select for the next one.
Find Out What Is Already Public
PrivacyOn scans 100+ data brokers and people-search sites for free and shows exactly where your name, address, phone number and family connections are listed. Paid plans from $8.33/month submit the removals for you, re-remove listings when brokers relist you, add dark web monitoring so you are told if your documents surface, and cover up to 5 family members. Run a free scan and see your exposure before someone else does.
Frequently Asked Questions
How many Revolut customers were affected by the 2026 data breach?
Revolut has not published a figure, describing it only as a "very limited group of customers." Reporting on the incident indicates the fraudulent requests named specific individuals rather than pulling bulk data, and appeared to focus on higher-value account holders. Revolut says it contacted affected customers directly through the app.
Was Revolut hacked?
No. There was no intrusion into Revolut's systems and customer funds were not affected. An impostor used a legitimate government agency email domain to submit fraudulent requests for customer information, and Revolut disclosed the data in response — a social-engineering failure of its request-review process rather than a technical compromise.
Is my money safe in my Revolut account?
Revolut has confirmed that customer funds were untouched and account systems were not breached. The risk from this incident is identity fraud carried out elsewhere using your documents, not direct theft from your Revolut balance. Still check transactions, beneficiaries and linked devices, and report anything unfamiliar via in-app chat.
What should I do if my passport or driver's license was exposed?
Treat it as permanently compromised. Notify your passport authority and DMV or equivalent, ask about flagging or reissuing the document, freeze your credit with all major bureaus, and keep the breach notification on file as evidence if you later need to dispute an account opened in your name.
Will I get more scam calls and emails after this breach?
Very likely, and better ones. Attackers who hold your date of birth, address and ID images can pass the informal "prove you're really my bank" checks most people rely on. Never confirm details to an inbound caller or emailer — end the contact and reconnect through the official app yourself.
How do I stop being an easy target for the next breach?
Cut the public data that lets someone select and profile you. Data brokers publish your address history, phone numbers, age and relatives, and that is where target lists come from. PrivacyOn removes those listings across 100+ brokers, keeps re-removing them as brokers relist, and adds dark web monitoring from $8.33/month — start with the free scan to see what is exposed today.