Revolut says a fraudster emailing from a real government domain obtained customer ID documents. What happened, what GDPR and AML rules require, and what to fix.
Table of contents
The Revolut data breach happened without any intrusion into Revolut's systems, the company says: a fraudster used a legitimate government agency email domain to request customer records, and received them. Affected customers were told the files included identity documents such as passports, and possibly verification selfies and transaction histories. Revolut says a limited number of customers were affected.
- Revolut confirmed on 12 September 2026 that it disclosed customer data after "fraudulent requests for information" sent from a legitimate government agency email domain.
- Its notice to affected customers listed dates of birth, addresses, phone numbers and copies of passports and driving licences, and said verification selfies, statements and transaction histories may also have been shared.
- Revolut has not named the agency, the markets involved or the number of customers, and says its systems and customer funds were unaffected.
- The FBI warned in November 2024 that compromised government email accounts were being sold and used for fraudulent emergency data requests.
- The obligation that matters most is not breach notification. It is who inside a regulated firm can release a complete KYC file, and on whose word.
What happened in the Revolut data breach?
Revolut says an unauthorised third party impersonated a government agency and obtained customer records by asking for them. The Revolut data breach surfaced when the crypto investigator ZachXBT flagged the customer notification on 12 September 2026, and Revolut confirmed the incident to TechCrunch the same day.
A Revolut spokesperson described "a sophisticated external impersonation scam", in which an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information. In remarks reported by the Irish Times, the company said it blocked the address and alerted the agency concerned, law enforcement, and data protection and financial regulators.
The scope of the Revolut data breach comes from two sources, and they differ. Revolut's customer notice, as reviewed by TechCrunch, listed identity and contact details plus passports and driving licences. ZachXBT's post adds IBANs, withdrawal records and occupations, and says the incident appeared targeted at high net worth users.
| Point | What is on the record | Source |
|---|---|---|
| Method | Fraudulent information requests from a legitimate government agency email domain | Revolut statement |
| Data listed in the customer notice | Name, date of birth, addresses, email, phone, passport or driving licence copies | Customer notice, via TechCrunch |
| Data that may have been shared | Verification selfies, account statements, transaction histories | Customer notice, via TechCrunch |
| Additional items reported | IBAN, withdrawal records, occupation, full transaction history including bitcoin | ZachXBT |
| Scale | "Limited", no number given | Revolut statement |
| Systems and funds | Unaffected, according to Revolut | Revolut statement |
| Not disclosed | Agency, markets, customer count | TechCrunch |
How do fake government data requests work?
A fake government data request exploits a channel built for speed. The FBI's Private Industry Notification 20241104-001, issued on 4 November 2024, describes criminals using compromised US and foreign government email addresses to send fraudulent emergency data requests and expose customer data.
The mechanism is urgency. The FBI explains that an emergency data request asks a business for information immediately, bypassing additional reviews of whether the request is legitimate. Criminals, it notes, use emergency requests, letterhead memorandums, subpoenas and mutual legal assistance requests interchangeably, and attach claims that someone will be harmed unless the data arrives fast.
The notice also documents a market for the access itself. A sender who controls a genuine government mailbox passes every check that looks only at the domain, which is why Revolut's description of a "legitimate government agency domain email" is the detail that matters. We do not know whether the account was compromised or misused from inside, and Revolut has not said.
| FBI-documented example | Date | What was offered or attempted |
|---|---|---|
| Forum sale of government email access | August 2024 | ".gov emails" for social engineering and data requests, with stolen subpoena documents |
| Forum claim of government mailboxes | March 2024 | Claimed control of government emails from over 25 countries, to obtain customer details |
| Fraudulent request to PayPal | March 2024 | A forged mutual legal assistance request, which PayPal denied |
| Paid tutorials | August 2023 | Lessons in writing emergency data requests, sold for 100 dollars |
Why is a KYC file worth more than a password?
A KYC file is valuable because it has already been verified. A passport copy paired with the selfie that matched it, plus an address and a transaction history, is the kit a fraudster needs to impersonate someone at another institution. A password can be reset in a minute. A passport takes weeks to replace, and a face cannot be replaced at all.
That is why the Revolut data breach belongs in the same conversation as vendor breaches like IDScan, even though Revolut says its systems were not breached. The route differs; the prize is the same. It also connects to the criminal markets behind the Xinbi Guarantee sanctions, where the UK says stolen personal data is sold to target victims.
The targeting reported by ZachXBT sharpens the point. Records of wealthy customers, with their home addresses and holdings, are useful for account takeover, extortion or social engineering. Revolut has not said what the requester was after.
What does the Revolut data breach mean for your obligations?
The Revolut data breach triggers familiar data protection duties, but the harder obligations sit in AML record-keeping and in how firms control disclosure. Five sets of duties apply to regulated firms holding identity documents for EU or UK customers, and each treats a forged request differently.
Breach notification under GDPR
Handing data to an impostor is a personal data breach, not a lawful disclosure. Article 33 GDPR requires notifying the supervisory authority "without undue delay and, where feasible, not later than 72 hours" after becoming aware, and documenting the facts and remedial action. Article 34 requires telling affected people directly where the risk to them is high. Revolut says it has contacted affected customers directly. The UK GDPR carries the same Articles 32 to 34 for UK customers.
An emailed request does not compel disclosure
A request is not a court order. In the UK, Schedule 2 paragraph 2 of the Data Protection Act 2018 lifts listed UK GDPR provisions for crime prevention only "to the extent that" applying them would be likely to prejudice it. That permits a disclosure; it does not require one, so the firm still owns the judgement about who is asking.
Security of processing covers people, not just systems
Article 32 requires technical and organisational measures, and names "unauthorised disclosure" as a risk to weigh. A requester verification procedure is exactly such a measure. Article 34 spares firms from telling individuals when the breached data was unintelligible, such as encrypted data, but that relief does nothing when staff decrypt and send a complete file on request.
AML record-keeping keeps the file in reach
Firms cannot simply delete KYC documents to shrink the target. Regulation 40 of the UK Money Laundering Regulations 2017 requires keeping a copy of customer due diligence documents for five years after the relationship ends. From 10 July 2027, Article 77 of the EU AML Regulation keeps a five-year duty but lets firms retain references instead of copies, if they can produce the information immediately and it cannot be altered.
Customer due diligence at every other firm
The exposed documents are now compromised credentials for onboarding elsewhere. Firms that onboard remotely should expect presentation of genuine documents by the wrong person, and weight document-plus-selfie matches accordingly, especially for high-value accounts. Regulation 28(11) already requires ongoing monitoring and keeping CDD information up to date, which is where sudden changes of contact details or devices on existing accounts should surface.
What is still uncertain about the Revolut data breach?
The biggest unknown is whether the government mailbox itself was compromised. If it was, other institutions may have received requests from the same address, and the agency, not Revolut, holds the evidence. Revolut has declined to name the agency, so other firms cannot check their own inboxes unless the agency or police warn them.
Scale and duration
Revolut says "limited" but gives no number, no markets and no timeline. Nobody outside the company knows how many requests were answered before detection, or whether each request named one customer or many. Those facts are likely to shape how regulators view it.
Who carries the liability
The agency's domain was genuine, according to Revolut, which calls the incident a sophisticated impersonation scam. The legal bar for avoiding responsibility is high: under Article 82(3) GDPR, a controller escapes compensation liability only if it proves it is "not in any way responsible" for the event. If the agency's mailbox was compromised, the agency may carry security and notification duties of its own. Revolut has not named the regulators it notified. Lithuania's State Data Protection Inspectorate opened an investigation into an earlier Revolut breach in September 2022.
A rule designed for paper
Retention rules assume the danger is losing records. This incident shows the danger of producing them too readily. The AML Regulation's references option lets firms hold less, but it arrives in July 2027 and still requires immediate production to competent authorities, which is precisely the pathway attackers imitate.
Know your requester
Onboarding checks are exhaustive; requester checks are rarely held to the same standard. Until law enforcement request channels are authenticated end to end, every firm that treats a genuine government domain as proof of a genuine official is exposed to the method behind the Revolut data breach.
How should compliance teams respond?
Compliance teams should treat any request to release customer data as a verification event, not an administrative task. The FBI's own advice is to "apply critical thinking to any emergency data requests received", check that cited legal codes match the claimed authority, and contact the sender and the originating authority when in doubt.
Use contact details you source yourself, never the ones in the request. Then narrow the blast radius. Limit who can export a full KYC file, require a second approver for any disclosure containing identity documents or selfies, and log every release against the request that justified it. Test the process with a simulated forged request, and add requester verification to your Article 32 documentation and your third-party breach risk review.
The Revolut data breach shows that a copy held centrally is a copy someone can be talked into sending. Zyphe verifies with an NFC chip read to ICAO 9303 and eIDAS standards and two-step liveness, with no image upload, and the customer holds the key to their own data, so there is no central store of passport images. Requester verification still matters for whatever a firm must produce. See how our storage works or book a demo.
The bottom line
The Revolut data breach did not need access to Revolut's systems, only a trusted email address and a request that was answered. For firms that hold verified identity documents, the weak point is often not the database but the people allowed to open it. Retention rules will keep those files in existence for years, so the durable controls are fewer copies, fewer people who can release them, and verification of every requester as seriously as every customer.
Cited sources
- TechCrunch, "Revolut confirms customer data breach through fake government requests", 12 September 2026
- ZachXBT, Telegram community alert on the Revolut customer notice, 12 September 2026
- Irish Times, Revolut statement on the impersonation scam, 14 September 2026
- FBI Private Industry Notification 20241104-001, fraudulent emergency data requests, 4 November 2024
- GDPR Article 33, notification of a personal data breach to the supervisory authority
- GDPR Article 34, communication of a personal data breach to the data subject
- GDPR Article 32, security of processing
- UK Money Laundering Regulations 2017, regulation 40, record-keeping
- UK Money Laundering Regulations 2017, regulation 28, ongoing monitoring
- Data Protection Act 2018, Schedule 2 paragraph 2, crime and taxation
- GDPR Article 82, right to compensation and liability
- Lithuanian State Data Protection Inspectorate, investigation into the 2022 Revolut breach
- Regulation (EU) 2024/1624, Article 77, record retention
- Regulation (EU) 2024/1624, Article 90, application from 10 July 2027
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.