TL;DR: Revolut confirmed it handed sensitive customer data to an unauthorized third party who sent fraudulent requests from a legitimate government agency email domain. Exposed details included birth dates, addresses, phone numbers, email addresses and copies of ID documents such as passports and driver's licences. If you bank with Revolut, expect follow-up phishing that uses those details.
👉 See if your data's already leaked — free 30-second check →
Revolut told affected customers that it released personal information after receiving fraudulent requests that appeared to come from a real government agency's email domain, according to TechCrunch's September 12, 2026 report. The company described it to the Irish Times as a sophisticated impersonation scam that affected a limited number of customers.
What was exposed
- Birth dates, postal addresses, email addresses and phone numbers.
- Copies of identity documents, including passports and driver's licences.
- Possibly verification selfies, account statements and transaction histories, according to Revolut's notification.
What is confirmed and what is only claimed
Revolut said it notified affected customers, the government agency involved, law enforcement and financial regulators. It did not say how many people were affected or in which countries. SecurityWeek later reported that hackers are demanding a $3 million ransom and that the data was allegedly obtained over five months through requests impersonating an Italian government agency. Those figures are reported claims, and we have not seen Revolut confirm them.
Why this matters even if you were not named
A name, phone number, email address and ID copy together are exactly what impersonators need to sound convincing. That is the mechanism behind how scammers build a convincing profile of you, and it is why breach victims often get calls that seem to know too much.
What to do now
- Treat any unexpected call, text or email claiming to be from Revolut as suspect. Open the app yourself instead of using a link or a number in the message.
- If a passport or licence copy was included, watch your credit file and be suspicious of surprise account or loan notices. The steps in re-securing your identity after a scam apply here too.
- Use a unique password and app-based two-factor authentication on your Revolut and email accounts.
- Read what a data breach notification email really means so you can tell a genuine notice from a phishing copy.
The same week, Telus customers in Canada were caught up in a confusing breach notice, covered in our Telus breach email guide.
FAQs
Was my Revolut account hacked?
Revolut's description is that data was released in response to fraudulent requests, not that customer accounts were logged into. Affected customers were said to have been contacted directly.
What should I do if I got a Revolut breach notice?
Verify it inside the Revolut app, be wary of calls or texts that mention your personal details, and monitor your credit file if an ID copy was involved.
Can scammers use a copy of my passport?
An ID copy alone is rarely enough, but it can support impersonation attempts. Watch for unexpected accounts, loans or verification requests in your name.
Once the immediate danger has passed, see how much of your information is already public: Use the free digital footprint checker.
Curious what's already out there? Scan My Shadow checks a phone number and email across 1,500+ sources and sends a clear report — no guesswork, just facts. Start your scan.
Sources
- TechCrunch: Revolut confirms customer data breach through fake government requests
- Irish Times: Revolut blames sophisticated impersonation scam for customer data breach
- SecurityWeek: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
