All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Your passport, your face, your bank statement, and your Bitcoin transaction history could be sitting on a hacker's server right now. Revolut, which has more than 80 million customers worldwide, has confirmed a “sophisticated” scam that tricked the company into handing sensitive customer information to an unauthorized party.[1]
Nobody hacked into Revolut's systems. Instead, an apparently legitimate government request, sent from an email address on a real government agency domain, passed the company's checks and prompted it to disclose customer information before it verified the request with the agency.
The attackers have reportedly started publishing some of the stolen information and are threatening to release more every day until Revolut pays.[2] This puts affected customers at risk of identity theft, highly targeted phishing, and financial fraud. But there are a few steps you can take to reduce the risk.
Revolut has been hit by security incidents before
How the leaked data could put you at risk
What can you do to protect yourself
The bigger lesson for your data security
What sensitive data did Revolut hand over
The breach compromised customers' personal details, including names, dates of birth, occupations, postal addresses, phone numbers, and email addresses, along with copies of identity documents such as driving licences and passports. Verification selfies, account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin activity, may also have been exposed.
Revolut said the breach resulted from a “sophisticated external impersonation scam,” in which threat actors used an email address on a legitimate government agency domain to submit fraudulent requests for information. The company fulfilled the request before independently confirming with the government agency that it was not legitimate.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” a Revolut spokesperson said. Revolut also said that its systems and customer funds were unaffected.
Revolut hasn’t disclosed how many individuals were impacted or whether the incident was limited to a specific market. It has described the number of affected customers as “limited” and said it contacted those customers directly.
According to International Cyber Digest, threat actors who obtained the information have reportedly started publishing it online and said they would continue releasing more data every day until Revolut pays.
The first published information reportedly included identity documents and verification selfies belonging to tennis player Alexander Shevchenko and Felix Römer, CEO of online crypto casino Gamdom.
Revolut has been hit by security incidents before
This isn't the first time Revolut has faced security problems. In September 2022, a social engineering attack exposed the personal data of 50,150 customers, including names, addresses, email addresses, phone numbers, and partial payment card information.
In the same year, criminals also exploited a vulnerability in Revolut's U.S. payment system to steal more than $20 million from the company. And in July 2026, a threat actor claimed to be selling 75 million Revolut records.
How the leaked data could put you at risk
The nature of the information exposed in this incident makes it particularly sensitive. Identity documents, contact information, and detailed financial records can give scammers a much more complete picture of their victims, creating several risks.
- Identity theft: The exposed information could give attackers enough information to attempt to impersonate victims. They could attempt to open accounts or apply for financial products in someone else's name. Verification selfies, meanwhile, could help attackers make fraudulent identity-verification attempts more convincing.
- Phishing scams: The information could also fuel convincing social engineering attacks. Scammers could impersonate Revolut support staff, financial institutions, cryptocurrency exchanges, or government agencies while using victims' own information to make their messages appear legitimate. The goal could be to trick victims into revealing passwords, one-time codes, or other sensitive information.
- Crypto privacy and targeted attacks: Leaked Bitcoin activity is particularly sensitive. Although blockchain transactions are pseudonymous and publicly visible, attackers could link them to personal information such as a name, address, or passport, potentially connecting a real identity to someone's on-chain activity and gaining insight into their cryptocurrency holdings and transaction history. This could make high-value crypto users more attractive targets for highly targeted phishing, extortion, or other attempts to steal their funds. The apparent targeting of high-net-worth users has been suggested by crypto investigator ZachXBT, but Revolut has not confirmed this.
- Financial profiling: Account statements and transaction histories could reveal information about a person's income, spending habits, financial relationships, and potentially their assets. That information could help scammers tailor financial fraud or social engineering attacks to their victims.
- Data permanence: There’s another problem with leaked identity documents and facial verification images: unlike a password, you cannot simply change them. Once copies of your passport or face have been exposed, they can potentially be retained and reused by threat actors in future scams or impersonation attempts.
What can you do to protect yourself
Revolut has contacted affected customers and says it has alerted law enforcement, regulators, and the relevant government agency. However, it has not publicly detailed any identity-restoration or fraud-monitoring support it will provide.
Here are some steps you can take to protect yourself in the meantime.
- Beware of phishing attempts: Be especially cautious with messages claiming to come from Revolut, government agencies, banks, or cryptocurrency services. Don’t click links or open attachments in unexpected messages. Consider using a reliable third-party antivirus program that can scan downloads for malware and provide real-time web protection to warn you about malicious websites before you visit them.
- Register with Cifas: If you’re in the UK, consider signing up for Cifas Protective Registration. It currently costs £30 for two years and places a warning against your personal details in the Cifas National Fraud Database. Member organisations can see the warning and carry out additional checks when someone attempts to use your identity to obtain financial products.
- Add a Notice of Correction: UK customers can also add a short Notice of Correction to their credit reports explaining that their personal information has been exposed and could be used for identity fraud. You need to contact each of the three main UK credit reference agencies — Experian, Equifax and TransUnion — separately. The notice can alert lenders to the risk, although it doesn’t itself prevent someone from applying for credit in your name.
- Monitor your financial accounts and crypto wallets: Keep a close eye on your bank and Revolut accounts, as well as your cryptocurrency accounts and wallets, for transactions you don’t recognize. If you spot anything suspicious, report it immediately to your bank, financial institution, or crypto provider.
- Use an identity theft protection service: These services can monitor breach databases and parts of the dark web for your personal information and alert you if your details appear. Some also offer identity theft restoration assistance, which can help you through the process of recovering from identity fraud if your information is misused.
The bigger lesson for your data security
The Revolut incident shows just how much damage can come from a data breach even when no customer funds are stolen and the company's core systems remain unaffected. Passports, selfies, addresses, and detailed financial and Bitcoin transaction histories can give scammers the information they need to build highly convincing identities and target victims with increasingly personalized fraud.
And perhaps the biggest lesson here is that data security doesn’t end with having a strong password or enabling two-factor authentication. You also need to think about what happens to the personal information you hand over to financial companies in the first place, as well as what you can do if that information is exposed.
You cannot control how a company verifies a government request, but you can take steps to limit what happens next. Keep a close eye on your financial and crypto accounts, consider additional identity protections such as Cifas if you're in the UK, and be particularly wary of messages that use your newly exposed personal information to appear legitimate.