Free guide: How to use AI in compliance
Back

The Revolut data breach: a forged government request and the KYC files it unlocked

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published September 14, 2026 Reviewed by Charlene Wang
Editorial illustration for the article "The Revolut data breach: a forged government request and the KYC files it unlocked".

Revolut says a fraudster emailing from a real government domain obtained customer ID documents. What happened, what GDPR and AML rules require, and what to fix.

Table of contents

The Revolut data breach happened without any intrusion into Revolut's systems, the company says: a fraudster used a legitimate government agency email domain to request customer records, and received them. Affected customers were told the files included identity documents such as passports, and possibly verification selfies and transaction histories. Revolut says a limited number of customers were affected.

  • Revolut confirmed on 12 September 2026 that it disclosed customer data after "fraudulent requests for information" sent from a legitimate government agency email domain.
  • Its notice to affected customers listed dates of birth, addresses, phone numbers and copies of passports and driving licences, and said verification selfies, statements and transaction histories may also have been shared.
  • Revolut has not named the agency, the markets involved or the number of customers, and says its systems and customer funds were unaffected.
  • The FBI warned in November 2024 that compromised government email accounts were being sold and used for fraudulent emergency data requests.
  • The obligation that matters most is not breach notification. It is who inside a regulated firm can release a complete KYC file, and on whose word.

What happened in the Revolut data breach?

Revolut says an unauthorised third party impersonated a government agency and obtained customer records by asking for them. The Revolut data breach surfaced when the crypto investigator ZachXBT flagged the customer notification on 12 September 2026, and Revolut confirmed the incident to TechCrunch the same day.

A Revolut spokesperson described "a sophisticated external impersonation scam", in which an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information. In remarks reported by the Irish Times, the company said it blocked the address and alerted the agency concerned, law enforcement, and data protection and financial regulators.

The scope of the Revolut data breach comes from two sources, and they differ. Revolut's customer notice, as reviewed by TechCrunch, listed identity and contact details plus passports and driving licences. ZachXBT's post adds IBANs, withdrawal records and occupations, and says the incident appeared targeted at high net worth users.

PointWhat is on the recordSource
MethodFraudulent information requests from a legitimate government agency email domainRevolut statement
Data listed in the customer noticeName, date of birth, addresses, email, phone, passport or driving licence copiesCustomer notice, via TechCrunch
Data that may have been sharedVerification selfies, account statements, transaction historiesCustomer notice, via TechCrunch
Additional items reportedIBAN, withdrawal records, occupation, full transaction history including bitcoinZachXBT
Scale"Limited", no number givenRevolut statement
Systems and fundsUnaffected, according to RevolutRevolut statement
Not disclosedAgency, markets, customer countTechCrunch

How do fake government data requests work?

A fake government data request exploits a channel built for speed. The FBI's Private Industry Notification 20241104-001, issued on 4 November 2024, describes criminals using compromised US and foreign government email addresses to send fraudulent emergency data requests and expose customer data.

The mechanism is urgency. The FBI explains that an emergency data request asks a business for information immediately, bypassing additional reviews of whether the request is legitimate. Criminals, it notes, use emergency requests, letterhead memorandums, subpoenas and mutual legal assistance requests interchangeably, and attach claims that someone will be harmed unless the data arrives fast.

The notice also documents a market for the access itself. A sender who controls a genuine government mailbox passes every check that looks only at the domain, which is why Revolut's description of a "legitimate government agency domain email" is the detail that matters. We do not know whether the account was compromised or misused from inside, and Revolut has not said.

FBI-documented exampleDateWhat was offered or attempted
Forum sale of government email accessAugust 2024".gov emails" for social engineering and data requests, with stolen subpoena documents
Forum claim of government mailboxesMarch 2024Claimed control of government emails from over 25 countries, to obtain customer details
Fraudulent request to PayPalMarch 2024A forged mutual legal assistance request, which PayPal denied
Paid tutorialsAugust 2023Lessons in writing emergency data requests, sold for 100 dollars

Why is a KYC file worth more than a password?

A KYC file is valuable because it has already been verified. A passport copy paired with the selfie that matched it, plus an address and a transaction history, is the kit a fraudster needs to impersonate someone at another institution. A password can be reset in a minute. A passport takes weeks to replace, and a face cannot be replaced at all.

That is why the Revolut data breach belongs in the same conversation as vendor breaches like IDScan, even though Revolut says its systems were not breached. The route differs; the prize is the same. It also connects to the criminal markets behind the Xinbi Guarantee sanctions, where the UK says stolen personal data is sold to target victims.

The targeting reported by ZachXBT sharpens the point. Records of wealthy customers, with their home addresses and holdings, are useful for account takeover, extortion or social engineering. Revolut has not said what the requester was after.

What does the Revolut data breach mean for your obligations?

The Revolut data breach triggers familiar data protection duties, but the harder obligations sit in AML record-keeping and in how firms control disclosure. Five sets of duties apply to regulated firms holding identity documents for EU or UK customers, and each treats a forged request differently.

Breach notification under GDPR

Handing data to an impostor is a personal data breach, not a lawful disclosure. Article 33 GDPR requires notifying the supervisory authority "without undue delay and, where feasible, not later than 72 hours" after becoming aware, and documenting the facts and remedial action. Article 34 requires telling affected people directly where the risk to them is high. Revolut says it has contacted affected customers directly. The UK GDPR carries the same Articles 32 to 34 for UK customers.

An emailed request does not compel disclosure

A request is not a court order. In the UK, Schedule 2 paragraph 2 of the Data Protection Act 2018 lifts listed UK GDPR provisions for crime prevention only "to the extent that" applying them would be likely to prejudice it. That permits a disclosure; it does not require one, so the firm still owns the judgement about who is asking.

Security of processing covers people, not just systems

Article 32 requires technical and organisational measures, and names "unauthorised disclosure" as a risk to weigh. A requester verification procedure is exactly such a measure. Article 34 spares firms from telling individuals when the breached data was unintelligible, such as encrypted data, but that relief does nothing when staff decrypt and send a complete file on request.

AML record-keeping keeps the file in reach

Firms cannot simply delete KYC documents to shrink the target. Regulation 40 of the UK Money Laundering Regulations 2017 requires keeping a copy of customer due diligence documents for five years after the relationship ends. From 10 July 2027, Article 77 of the EU AML Regulation keeps a five-year duty but lets firms retain references instead of copies, if they can produce the information immediately and it cannot be altered.

Customer due diligence at every other firm

The exposed documents are now compromised credentials for onboarding elsewhere. Firms that onboard remotely should expect presentation of genuine documents by the wrong person, and weight document-plus-selfie matches accordingly, especially for high-value accounts. Regulation 28(11) already requires ongoing monitoring and keeping CDD information up to date, which is where sudden changes of contact details or devices on existing accounts should surface.

What is still uncertain about the Revolut data breach?

The biggest unknown is whether the government mailbox itself was compromised. If it was, other institutions may have received requests from the same address, and the agency, not Revolut, holds the evidence. Revolut has declined to name the agency, so other firms cannot check their own inboxes unless the agency or police warn them.

Scale and duration

Revolut says "limited" but gives no number, no markets and no timeline. Nobody outside the company knows how many requests were answered before detection, or whether each request named one customer or many. Those facts are likely to shape how regulators view it.

Who carries the liability

The agency's domain was genuine, according to Revolut, which calls the incident a sophisticated impersonation scam. The legal bar for avoiding responsibility is high: under Article 82(3) GDPR, a controller escapes compensation liability only if it proves it is "not in any way responsible" for the event. If the agency's mailbox was compromised, the agency may carry security and notification duties of its own. Revolut has not named the regulators it notified. Lithuania's State Data Protection Inspectorate opened an investigation into an earlier Revolut breach in September 2022.

A rule designed for paper

Retention rules assume the danger is losing records. This incident shows the danger of producing them too readily. The AML Regulation's references option lets firms hold less, but it arrives in July 2027 and still requires immediate production to competent authorities, which is precisely the pathway attackers imitate.

Know your requester

Onboarding checks are exhaustive; requester checks are rarely held to the same standard. Until law enforcement request channels are authenticated end to end, every firm that treats a genuine government domain as proof of a genuine official is exposed to the method behind the Revolut data breach.

How should compliance teams respond?

Compliance teams should treat any request to release customer data as a verification event, not an administrative task. The FBI's own advice is to "apply critical thinking to any emergency data requests received", check that cited legal codes match the claimed authority, and contact the sender and the originating authority when in doubt.

Use contact details you source yourself, never the ones in the request. Then narrow the blast radius. Limit who can export a full KYC file, require a second approver for any disclosure containing identity documents or selfies, and log every release against the request that justified it. Test the process with a simulated forged request, and add requester verification to your Article 32 documentation and your third-party breach risk review.

The Revolut data breach shows that a copy held centrally is a copy someone can be talked into sending. Zyphe verifies with an NFC chip read to ICAO 9303 and eIDAS standards and two-step liveness, with no image upload, and the customer holds the key to their own data, so there is no central store of passport images. Requester verification still matters for whatever a firm must produce. See how our storage works or book a demo.

The bottom line

The Revolut data breach did not need access to Revolut's systems, only a trusted email address and a request that was answered. For firms that hold verified identity documents, the weak point is often not the database but the people allowed to open it. Retention rules will keep those files in existence for years, so the durable controls are fewer copies, fewer people who can release them, and verification of every requester as seriously as every customer.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Revolut says a third party used a legitimate government agency email domain to send fraudulent requests for customer information, and the bank disclosed data in response. Affected customers were told the files included identity and contact details and passport or driving licence copies, and may have included verification selfies, account statements and transaction histories. Revolut says systems and funds were unaffected.

Revolut says its systems were not breached. The company describes an external impersonation scam, in which data left through a disclosure process after requests from what Revolut calls a legitimate government agency email domain. Revolut has not said whether the agency's email account had itself been compromised, which would be a hack of the agency rather than the bank.

Revolut has only said the number is limited and that affected customers were contacted directly. It has not disclosed a figure, the markets involved or how long the requests continued. The crypto investigator ZachXBT, who first publicised the customer notice, said the incident appeared to target high net worth users.

It is a forged request, often sent from a compromised government or police email account, asking a company to release customer data urgently. The FBI warned in a November 2024 notice that emergency requests bypass additional reviews of legitimacy, and that criminals sell access to government mailboxes and templates for these requests.

Not freely. UK and EU anti-money laundering rules require firms to keep copies of customer due diligence documents for five years after a relationship ends. From 10 July 2027, the EU AML Regulation will let firms keep references instead of copies, provided they can still produce the information immediately to competent authorities.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo