Revolut Gave Customers' Verification Selfies to a Fake Government Email. Here's What to Do Now

A fake government request exposed highly sensitive Revolut customer data, leaving users vulnerable to identity theft, fraud, and targeted phishing attacks.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Your passport, your face, your bank statement, and your Bitcoin transaction history could be sitting on a hacker's server right now. Revolut, which has more than 80 million customers worldwide, has confirmed a “sophisticated” scam that tricked the company into handing sensitive customer information to an unauthorized party.[1]

Nobody hacked into Revolut's systems. Instead, an apparently legitimate government request, sent from an email address on a real government agency domain, passed the company's checks and prompted it to disclose customer information before it verified the request with the agency.

The attackers have reportedly started publishing some of the stolen information and are threatening to release more every day until Revolut pays.[2] This puts affected customers at risk of identity theft, highly targeted phishing, and financial fraud. But there are a few steps you can take to reduce the risk.

In this article
What sensitive data did Revolut hand over
Revolut has been hit by security incidents before
How the leaked data could put you at risk
What can you do to protect yourself
The bigger lesson for your data security

What sensitive data did Revolut hand over

The breach compromised customers' personal details, including names, dates of birth, occupations, postal addresses, phone numbers, and email addresses, along with copies of identity documents such as driving licences and passports. Verification selfies, account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin activity, may also have been exposed.

Revolut said the breach resulted from a “sophisticated external impersonation scam,” in which threat actors used an email address on a legitimate government agency domain to submit fraudulent requests for information. The company fulfilled the request before independently confirming with the government agency that it was not legitimate.

“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” a Revolut spokesperson said. Revolut also said that its systems and customer funds were unaffected.

Revolut hasn’t disclosed how many individuals were impacted or whether the incident was limited to a specific market. It has described the number of affected customers as “limited” and said it contacted those customers directly.

According to International Cyber Digest, threat actors who obtained the information have reportedly started publishing it online and said they would continue releasing more data every day until Revolut pays.

The first published information reportedly included identity documents and verification selfies belonging to tennis player Alexander Shevchenko and Felix Römer, CEO of online crypto casino Gamdom.

Revolut has been hit by security incidents before

This isn't the first time Revolut has faced security problems. In September 2022, a social engineering attack exposed the personal data of 50,150 customers, including names, addresses, email addresses, phone numbers, and partial payment card information.

In the same year, criminals also exploited a vulnerability in Revolut's U.S. payment system to steal more than $20 million from the company. And in July 2026, a threat actor claimed to be selling 75 million Revolut records.

How the leaked data could put you at risk

The nature of the information exposed in this incident makes it particularly sensitive. Identity documents, contact information, and detailed financial records can give scammers a much more complete picture of their victims, creating several risks.

  1. Identity theft: The exposed information could give attackers enough information to attempt to impersonate victims. They could attempt to open accounts or apply for financial products in someone else's name. Verification selfies, meanwhile, could help attackers make fraudulent identity-verification attempts more convincing.
  2. Phishing scams: The information could also fuel convincing social engineering attacks. Scammers could impersonate Revolut support staff, financial institutions, cryptocurrency exchanges, or government agencies while using victims' own information to make their messages appear legitimate. The goal could be to trick victims into revealing passwords, one-time codes, or other sensitive information.
  3. Crypto privacy and targeted attacks: Leaked Bitcoin activity is particularly sensitive. Although blockchain transactions are pseudonymous and publicly visible, attackers could link them to personal information such as a name, address, or passport, potentially connecting a real identity to someone's on-chain activity and gaining insight into their cryptocurrency holdings and transaction history. This could make high-value crypto users more attractive targets for highly targeted phishing, extortion, or other attempts to steal their funds. The apparent targeting of high-net-worth users has been suggested by crypto investigator ZachXBT, but Revolut has not confirmed this.
  4. Financial profiling: Account statements and transaction histories could reveal information about a person's income, spending habits, financial relationships, and potentially their assets. That information could help scammers tailor financial fraud or social engineering attacks to their victims.
  5. Data permanence: There’s another problem with leaked identity documents and facial verification images: unlike a password, you cannot simply change them. Once copies of your passport or face have been exposed, they can potentially be retained and reused by threat actors in future scams or impersonation attempts.

What can you do to protect yourself

Revolut has contacted affected customers and says it has alerted law enforcement, regulators, and the relevant government agency. However, it has not publicly detailed any identity-restoration or fraud-monitoring support it will provide.

Here are some steps you can take to protect yourself in the meantime.

  1. Beware of phishing attempts: Be especially cautious with messages claiming to come from Revolut, government agencies, banks, or cryptocurrency services. Don’t click links or open attachments in unexpected messages. Consider using a reliable third-party antivirus program that can scan downloads for malware and provide real-time web protection to warn you about malicious websites before you visit them.
  2. Register with Cifas: If you’re in the UK, consider signing up for Cifas Protective Registration. It currently costs £30 for two years and places a warning against your personal details in the Cifas National Fraud Database. Member organisations can see the warning and carry out additional checks when someone attempts to use your identity to obtain financial products.
  3. Add a Notice of Correction: UK customers can also add a short Notice of Correction to their credit reports explaining that their personal information has been exposed and could be used for identity fraud. You need to contact each of the three main UK credit reference agencies — Experian, Equifax and TransUnion — separately. The notice can alert lenders to the risk, although it doesn’t itself prevent someone from applying for credit in your name.
  4. Monitor your financial accounts and crypto wallets: Keep a close eye on your bank and Revolut accounts, as well as your cryptocurrency accounts and wallets, for transactions you don’t recognize. If you spot anything suspicious, report it immediately to your bank, financial institution, or crypto provider.
  5. Use an identity theft protection service: These services can monitor breach databases and parts of the dark web for your personal information and alert you if your details appear. Some also offer identity theft restoration assistance, which can help you through the process of recovering from identity fraud if your information is misused.

The bigger lesson for your data security

The Revolut incident shows just how much damage can come from a data breach even when no customer funds are stolen and the company's core systems remain unaffected. Passports, selfies, addresses, and detailed financial and Bitcoin transaction histories can give scammers the information they need to build highly convincing identities and target victims with increasingly personalized fraud.

And perhaps the biggest lesson here is that data security doesn’t end with having a strong password or enabling two-factor authentication. You also need to think about what happens to the personal information you hand over to financial companies in the first place, as well as what you can do if that information is exposed.

You cannot control how a company verifies a government request, but you can take steps to limit what happens next. Keep a close eye on your financial and crypto accounts, consider additional identity protections such as Cifas if you're in the UK, and be particularly wary of messages that use your newly exposed personal information to appear legitimate.

4.8
Editorial Rating
Get Deal
On LifeLock's website
2026 Editors’ Choice
Best ID Theft Service for Comprehensive Monitoring
Identity Protection
LifeLock
  • ID theft protection with U.S.-based restoration specialists and data removal services included on every plan
  • ID theft insurance on all plans, with the Total plan covering up to $3M
  • Dark web, home title, and social media monitoring available, with coverage expanding by plan tier

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Revolut confirms customer data breach through fake government requests

[2] International Cyber Digest on X