Revolut Gave Customer Passports to a Fake Government Request. What It Teaches About Your Data
Revolut released customer ID documents and account data to someone using a real government email domain. How the trick works, what affected customers should do, and why the number of copies of your financial data matters.
Around 11 September 2026, some Revolut customers received a letter from the company saying their personal data had been sent to someone who should never have had it. Nobody broke into Revolut’s servers. Revolut received what looked like an official information request from a government agency and answered it.
The request came from a real government email domain. The person who sent it had no authority to use that domain.
What Revolut has confirmed
Revolut told TechCrunch on 12 September that an “unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” Once it found out, the company blocked the address and alerted the agency, law enforcement, and data protection and financial regulators. It says its systems and customer funds were unaffected.
According to the same statement, the data sent out included dates of birth, postal and email addresses, phone numbers, and copies of passports and driving licences. Revolut said it may also have included verification selfies, account statements, and transaction histories.
Revolut has not named the agency, has not said which country the request came from, and has only described the number of affected customers as limited.
Some details come from customer notices shared publicly by the blockchain investigator ZachXBT and reported by CoinDesk and CyberInsider, not from Revolut’s statement: occupations, IBANs, withdrawal records, and Bitcoin transaction activity. ZachXBT also suggested the requests may have been aimed at wealthy customers. Treat those points as reported until Revolut confirms them.
Why the security checks passed
Companies that hold personal data get legitimate requests from police and government bodies every day, and they have processes for answering them. One check in that process looks at whether an email came from the domain it claims to be from. This one did.
Domain checks prove where a message was sent from. They cannot prove who was typing. If a criminal gets into a real police or government mailbox, every message they send passes those checks.
This is a known and growing problem. In November 2024 the FBI warned US companies that login details for police and government email accounts were being sold on criminal forums and used to send fake emergency data requests. Emergency requests are the riskiest kind, because they exist for cases involving imminent harm and skip the court paperwork a normal request needs. The FBI notice was about US companies; the Revolut case shows the same playbook working against a European bank.
Revolut has been caught by social engineering before. In September 2022, an attacker who talked their way in obtained the personal details of 50,150 customers.
The data you cannot change
Most breach advice is about passwords, and passwords can be reset. Almost nothing that left Revolut can be.
You cannot get a new date of birth. Replacing a passport takes weeks and money, and the selfie is still your face. Your transaction history already happened; it records where you shop, when you are paid, and how much you have.
That history is what makes this leak useful to a scammer. Most people treat “they knew my real details” as proof a caller is genuine. Someone who can read out your last five card payments and the date you opened your account sounds exactly like your bank’s fraud team, and that is the call that ends with you moving money to a “safe account.”
If Revolut wrote to you
Revolut has told affected customers to watch for targeted phishing, identity theft, and SIM-swap attempts. In practice, that means:
- Assume any call, text, or email about your account is fake, however much it knows about you. End it, then open the Revolut app yourself. A real problem will show up there.
- Ask your mobile carrier for a port-out or SIM lock. A SIM swap hands your text-message codes to someone else, and the leaked phone number plus ID copies make one easier to request.
- Freeze your credit, or add fraud protection. In the US, a credit freeze with Equifax, Experian, and TransUnion is free. In the UK, Cifas Protective Registration adds extra checks when someone applies for credit in your name.
- Find out exactly what was sent. If you are in the UK or EU, data protection law lets you make a subject access request asking Revolut which of your data it holds and who it has been disclosed to. That gives you a definite list to act on instead of a “may have included.”
- Change nothing because of an inbound message. Update contact details, passwords, or security settings only from inside the app or by typing the address yourself.
Every copy is another inbox
Revolut has to hold your passport. Banks are legally required to verify who you are, and nobody can open an account without handing that over. No choice you make changes that part.
The part you do control is how many other companies hold a copy of your financial life. Each one runs its own request process, its own support desk, and its own inboxes that a forged request can land in. A budgeting app that links to your bank usually adds at least two copies, one at the app and one at the data aggregator in the middle. We wrote about that chain in what a bank-linked budgeting app actually sees.
You can count those copies. Open your bank’s settings, find the list of connected apps, and remove the ones you no longer use. That removes their access from now on; old copies may still sit with the app or the aggregator until you ask them to delete it.
Where SelfCapsule fits
SelfCapsule Finance keeps your transactions in an encrypted database on your iPhone, iPad, or Mac. There is no SelfCapsule server holding a copy of them, so a forged request sent to us would find no transaction data to hand over.
The app does touch the network in a few narrow cases. If you have a Pro license key, it checks that key with our license provider when you activate it and each time the app opens, sending only the key and an activation ID. On iPhone and iPad, purchases go through the App Store. On the Mac, it checks for updates when you click the button, and downloads a local AI model only if you choose one. Exchange rates are typed in by you, never fetched. None of those carry your transactions, budgets, or balances.
This does not change what your bank holds. It means your budget adds no extra copy of your spending anywhere else.
Your finances. Contained. Get SelfCapsule Finance on the App Store, or download the Mac version from selfcapsule.com.
Sources
- TechCrunch, “Revolut confirms customer data breach through fake government requests,” 12 September 2026: https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
- CoinDesk, 12 September 2026: https://www.coindesk.com/tech/2026/09/12/bitcoin-activity-passports-exposed-after-revolut-falls-for-fake-government-request
- CyberInsider, 13 September 2026: https://cyberinsider.com/revolut-handed-customer-data-to-fraudsters-using-a-government-email-domain/
- Krebs on Security on the FBI notice, November 2024: https://krebsonsecurity.com/2024/11/fbi-spike-in-hacked-police-emails-fake-subpoenas/
- CS Hub on the 2022 Revolut incident, 21 September 2022: https://www.cshub.com/attacks/news/revolut-data-breach-exposes-information-for-more-than-50000-customers