Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial and Passport Data

Revolut Discloses Data Breach via Government-Impersonation (TL-2026-2498) is a high-severity data breach, first published 2026-09-14. It has no confirmed attribution, affects Revolut Revolut customer KYC/compliance data (identity documents, maps to 10 MITRE ATT&CK techniques (T1048, T1078, T1199), and is covered by 9 detection rules and 13 indicators of compromise.

Key facts for TL-2026-2498

Threat ID
TL-2026-2498
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-14
Last reviewed
2026-09-14
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, fintech, banking, cryptocurrency
Target regions
Global
Detection rules
9
Indicators of compromise
13

Revolut disclosed a data breach in which an unauthorized third party used a legitimate, domain-authenticated government agency email account to submit fraudulent requests for customer information, which Revolut staff fulfilled as a routine legal-compliance request. Exposed data for a limited number of customers — reportedly skewed toward high-net-worth individuals — includes passports/driver's licenses, KYC verification selfies, IBANs, account statements, and full transaction histories including Bitcoin activity; the threat actor has since begun publicly leaking samples on X and Telegram while demanding roughly 10,000 BTC (~$782M) not to release more.

How Revolut Discloses Data Breach via Government-Impersonation works

On September 12, 2026, UK-based neobank Revolut confirmed a data breach stemming not from a technical intrusion but from abuse of its legal/regulatory information-request process. Revolut stated: "Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency's email domain," and that because "the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request." Revolut has declined to name the government agency involved, the country/market affected, or the number of impacted customers, describing it only as a "sophisticated external impersonation scam" affecting a "limited number of customers."

Customer notifications sent around September 11, 2026 indicate the exposed data set includes full name, date of birth, occupation, postal address, email, and phone number; copies of passports and/or driver's licenses; KYC facial-verification selfies; and financial records comprising account statements, IBANs, withdrawal records, and complete transaction histories including Bitcoin-related activity. Revolut says its core systems and customer funds were not compromised — this was a data-disclosure incident against the compliance/KYC request-handling workflow, not a platform intrusion.

On-chain investigator ZachXBT added detail Revolut's notification omitted, stating the operation appears to have specifically targeted high-net-worth users, assessing the goal as building "detailed profiles of wealthy individuals, using their KYC documents and cryptocurrency transaction history linked to their real identities" for potential downstream "fraud, impersonation, or extortion" — a population facing elevated risk of SIM-swapping and physical/cryptocurrency-focused extortion once identity and holdings data is exposed.

The incident escalated on September 13, 2026 when a threat actor began posting leaked identity documents and selfies on X (Twitter) and Telegram, naming specific individuals including professional tennis player Alexander Shevchenko and Felix Römer, CEO of Gamdom and Skinscom (Römer responded publicly on X: "Ah wtf @Revolut"). The Register additionally reported leaked samples attributed to "CEOs, sports professionals, and performing artists." The actor stated: "We're gonna start releasing more and more data everyday until Revolut pays for leaking their customers," separately claimed it would release "more messages, data and commentary on how Revolut's team operates," and accused Revolut of "handing information to countries outside its jurisdiction" and of general negligence around privacy. The actor also demanded a reported ~10,000 BTC (approximately $782M USD) to halt further leaks — a figure surfaced publicly by the dark-web-monitoring account DailyDarkWeb, which itself cautioned that the attacker's identity, the ransom figure, the claimed high-profile victim list, and the authenticity of the leaked material were all unconfirmed and uncorroborated as of publication.

Revolut says it immediately blocked the malicious email address on detection and notified the relevant government agency, law enforcement, data-protection authorities, and financial regulators; it declined to name the impersonated agency on the stated grounds that doing so "would allow other regulated platforms to search their own legal-request logs for messages from the same mailbox." Security researchers questioned Revolut's controls: Muhammad Yahya Patel of Huntress asked why "a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it," while Jamie Akhtar of CyberSmart characterized the exposed data set as "a complete identity theft kit" carrying downstream identity-fraud and phishing risk. This is not Revolut's first disclosed breach — the company reported a separate 2022 incident affecting 50,150 customers — underscoring a structural weakness common across fintech/KYC-handling organizations: reliance on email domain authentication (DKIM/SPF-style checks) alone as a trust signal for high-sensitivity legal/regulatory data requests, without an out-of-band verification step (e.g., callback to a known point of contact) before releasing PII, identity documents, or financial records.

MITRE ATT&CK techniques used in TL-2026-2498

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Defense Evasion

T1078 Valid Accounts; T1684.001 Impersonation

Initial Access

T1199 Trusted Relationship

Collection

T1213 Data from Information Repositories

Resource Development

T1586.002 Email Accounts

Reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1598 Phishing for Information

Impact

T1657 Financial Theft

Affected products and versions in Revolut Discloses Data Breach via Government-Impersonation

  • Revolut — Revolut customer KYC/compliance data (identity documents, verification selfies, financial records)
    Vulnerable versions: A limited, undisclosed subset of Revolut's global personal customer base (Revolut serves 80M+ personal and 800K+ business customers), reportedly skewed toward high-net-worth individuals

Remediation for Revolut Discloses Data Breach via Government-Impersonation

Immediate actions

  • Treat inbound legal/government/law-enforcement data-request emails as untrusted regardless of passing DKIM/SPF/DMARC — domain authentication proves the sending infrastructure, not the requester's legitimate authority to request the data.
  • Require out-of-band verification (callback to a published, pre-verified agency contact number — never a number or reply address supplied in the request itself) before releasing any KYC, identity-document, or financial-record data in response to a legal/government request.
  • Audit and, if needed, revoke standing trust granted to any mailbox or workflow that can trigger bulk release of customer PII/KYC data based on email content alone.
  • Monitor dark-web/leak-site and social-media (X, Telegram) channels for further disclosure of the stolen data set to scope exposure and support customer notification.

Workarounds

  • Pending process hardening, require dual-approval (two-person authorization) for any KYC/PII bulk release triggered by an external request.

Longer-term hardening

  • Implement a formal legal-request-intake process with identity verification of the requesting officer/agency independent of the inbound email (e.g., verified portal, signed legal process, or agency liaison contact list) before any compliance team member can fulfill a data request.
  • Apply data minimization and need-to-know segmentation so no single compliance workflow can export full KYC dossiers (ID scans + selfie + IBAN + full transaction history) in one action.
  • Add anomaly detection/alerting on bulk exports of KYC/identity-document data triggered by inbound email-based requests.
  • Run social-engineering/BEC tabletop exercises specifically simulating spoofed or compromised government/law-enforcement data-request emails against compliance and legal teams.

Timeline of Revolut Discloses Data Breach via Government-Impersonation

  • Revolut disclosed a separate, earlier data breach affecting 50,150 customers, establishing that this is not the company's first customer-data exposure incident.
  • Revolut begins emailing affected customers to notify them their identity documents, selfies, and financial records were exposed.
  • Revolut states it alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators, and confirms core systems and customer funds are unaffected.
  • Revolut publicly confirms the breach, describing it as a 'sophisticated external impersonation scam' in which an unauthorised email account used a legitimate government agency's domain to submit fraudulent information requests.
  • The threat actor expands its public messaging beyond the ransom demand, accusing Revolut of 'handing information to countries outside its jurisdiction' and of general negligence around privacy, and threatens to release 'more messages, data and commentary on how Revolut's team operates.'
  • Named leak victim Felix Römer, CEO of Gamdom and Skinscom, publicly responds to the leak on X with 'Ah wtf @Revolut.'
  • On-chain investigator ZachXBT publicizes that the breach appears specifically targeted at high-net-worth Revolut customers, assessing the likely goal as building identity/financial dossiers for downstream fraud, impersonation, or extortion — detail omitted from Revolut's own customer notification.
  • The threat actor demands a reported ~10,000 BTC (~$782M USD) and threatens to release additional stolen data every day until Revolut pays, per posts surfaced by dark-web-monitoring account DailyDarkWeb.
  • A threat actor begins posting leaked identity documents and verification selfies on X and Telegram, naming individuals including tennis player Alexander Shevchenko and Gamdom/Skinscom CEO Felix Römer.
  • Security researchers publicly question Revolut's verification controls: Huntress's Muhammad Yahya Patel and CyberSmart's Jamie Akhtar characterize the incident as reflecting insufficiently rigorous request-verification processes for a regulated financial institution.
  • Security and tech media (BleepingComputer, TechCrunch, The Register, Help Net Security, Security Affairs, Infosecurity Magazine, and others) widely report on the breach, its social-engineering attack vector, and the ongoing extortion attempt.

Sources cited for Revolut Discloses Data Breach via Government-Impersonation

More in data breach

Detection coverage for TL-2026-2498

As of 2026-09-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2498 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats