Revolut data leak: why the next scam may know your name

by

On the night of September 11, a customer notification from Revolut began circulating online, shared by the on-chain investigator ZachXBT among others and picked up by the trade press within hours.

By the following day, the company had confirmed its substance.

An unauthorized third party, writing from an email address on a legitimate government agency’s domain, had submitted requests for customer information.

Revolut’s staff handled the requests as they came in and released the data.

The company calls it “a sophisticated external impersonation scam.”

According to the customer notice, the requests carried genuine domain authentication credentials, which led Revolut to believe they were authentic; Infosecurity Magazine reports that they were processed as standard legal-compliance requests.

The notice also says Revolut independently contacted the agency to validate the request and alerted it to the unauthorized account operating on its domain.

When the deception was identified, Revolut blocked the address and notified the agency, law enforcement, and the relevant regulators. Its systems were not breached, and no customer funds were touched.

The Financial Times reported on September 15, citing people familiar with the matter, that the company had contacted about 680 people it believed were affected.

Revolut itself has not published a figure; its statements describe the group as very limited.

Which agency was impersonated and over what period requests were honored have not been disclosed either.

What left the building

According to the notification sent to affected customers, as reported by TechCrunch and The Block, the disclosed data included full name, date of birth, occupation, home address, email address, and phone number, along with copies of passports or driving licenses and the facial verification image submitted during onboarding.

The financial layer included account statements with IBANs, plus withdrawal records.

Full transaction histories were also listed, and several outlets reported that these included Bitcoin activity.

The notice adds that no biometric facial telemetry data was involved, drawing a line between the selfie image itself and the biometric data derived from it.

The notice lists categories that may have been disclosed, so not every affected person necessarily had every category exposed.

Read that as a list, and it looks like the standard breach inventory.

Read it as a single file about one person, and it looks like something else: a verified identity, a face to match it, a place to find them, the state of their finances and, for some, a record of where their crypto has been.

On September 13, the incident took a different shape.

Files described as belonging to Revolut customers began appearing on Telegram, accompanied by a promise to publish more every day until the company pays.

The Register, which reviewed the posts, and other outlets reported a demand of 10,000 Bitcoin.

None of this has official confirmation: Revolut has declined to comment on the ransom, and neither the company nor law enforcement has confirmed who is posting or whether every file is authentic.

What can be said is that the pressure now runs through the customers rather than the bank: each new file turns an abstract “limited group” into a named person with a published passport.

Why is this not a footnote

The comfortable reading is that someone believed an email. That is accurate, and it is not the point.

No system was intruded upon. The requests came through the channel built to receive them and were handled by the team whose job is to handle them.

Banks are legally obliged to respond to lawful information requests from authorities; a bank that could not do so would face a different kind of compliance problem.

The gap sits between two questions that are easy to conflate: is this message genuinely from that domain, and is this request genuinely authorized? The messages passed domain authentication.

What additional authorization checks were performed before the information was released has not been publicly established.

Domain authentication answers one question: did this message really come from that server. It says nothing about who is behind the account or whether they have the authority to ask. Domain authentication alone should not be treated as proof that a request for sensitive data is authorized. The stronger safeguard is structural, not merely a matter of staff vigilance: a request for sensitive data must be confirmed through a channel the requester did not choose, and no single person should be able to complete the release alone. That is true for a bank, and it is true for anyone else holding this kind of file.

Head of Infrastructure, SimpleSwap
Stefan Lauer

The technique is not new. In 2022, Bloomberg reported that Apple and Meta had handed user data to people sending forged emergency requests from compromised law-enforcement email accounts.

Discord confirmed it had done the same, noting that its checks had verified the account was genuine before it became apparent that it had been taken over.

The same year, Revolut disclosed a breach affecting roughly 50,000 customers, also achieved through social engineering, though in that case the attacker gained access to an internal database.

Four years on, the same class of attack has worked against a company that now serves more than 80 million people, received a full UK banking license in March, and, on September 3, received preliminary conditional approval from the US Office of the Comptroller of the Currency for a national bank charter.

None of that makes Revolut uniquely careless. It makes a narrower point: scale and regulatory maturity do not, on their own, close this particular gap.

Any organization that holds identity documents and is obliged to answer official requests has the same seam. Most have simply not been tested on it yet.

Why it matters more if you hold crypto

In August, we published a piece on the Trezor and Ledger customer data leaks and argued that a stolen shipping address is worth more than it seems, because the value of leaked data emerges when fields are joined. A phone number on its own decides nothing.

A phone number plus a recent hardware-wallet order plus the street it shipped to is a qualified list of confirmed holders.

The Revolut file is that argument with the joining already done.

Nobody has to cross-reference anything. The dossier arrives complete, and it carries two things the hardware-wallet leaks did not: a verified document with a matching selfie and a financial history.

The document and selfie matter because they are commonly used for identity verification.

Once both are in circulation, they provide unusually strong material for impersonation, attempted identity fraud, and more convincing social engineering.

They do not automatically defeat modern identity-verification controls, but they are significantly more useful to an attacker than basic contact data alone.

The transaction history matters for a different reason. On-chain transactions are public and permanent; what was private was the link between them and a legal name.

Where a Revolut statement records transfers to or from external wallets, that link is now in someone’s possession, and the involved addresses can be monitored.

A large incoming transfer months from now will be visible to a person who already knows where you live. As we noted in August, CertiK counted 52 verified physical attacks on crypto holders worldwide in the first half of this year, a third more than in the same period of 2025, and noted that as long as crypto holdings stay linked to identifiable financial data, physical coercion remains an attractive path for attackers.

When an identifiable crypto holder is tied to a physical address and to evidence of meaningful crypto activity, the physical-security risk rises materially.

What comes next

Every large identity data leak has been followed by a wave of contact that uses it. Ledger customers continue to be targeted by phishing campaigns, including physical letters reported in 2026, six years after the company’s 2020 breach; the source of the targeting data used in those campaigns has not been established.

There is no reason to expect this one to behave differently, and two reasons to expect it to be worse: the data is richer, and the incident itself is now the pretext.

The first messages will reference the leak directly.

Someone claiming to be Revolut, contacting affected customers with a link to verify their identity or secure their account.

Then a second circle: parties who are not Revolut but know you use it.

A wallet provider warning you about exposure. A regulator with a case number.

A law firm assembling claimants. A service that scrubs your data from the leak for a fee.

Somewhere in the sequence, for anyone whose statement showed crypto, comes the line that moves the money: your funds are at risk; transfer them to this secure address while we resolve it. Months later, recovery services will approach the people for whom that worked.

Not everyone contacted will be on the list. Scammers do not confine themselves to the actual affected group; the coverage makes the pretext plausible for any of Revolut’s customers, and few people can say with confidence which of their providers have had an incident this year. The noise rises for everyone.

“A password has a half-life of minutes once you know it leaked. A passport scan and a transaction history have a half-life of years. The people who buy this kind of data are not in a hurry. The correct assumption is that it will be used, and that it will be used later,” Stefan Lauer said.

What to do now

If you received the notification. Assume everything in it is in circulation and act on that basis.

Where your issuing authority allows it, replace the document; a new passport number makes the old scan a worse tool.

Most countries have a fraud-prevention register or credit-bureau flag that raises the bar for opening accounts in your name. Watch for credit applications or SIM changes you did not initiate.

Revolut has said it is supporting affected customers; ask through the in-app chat what that support includes.

Treat knowledge as no proof at all. Someone who knows your date of birth and your last three transactions has read a file.

That is the only thing it proves. Legitimate institutions do not establish their identity by reciting yours.

Do not act on inbound contact. Not an email, not a call, not a letter, not a QR code.

Close it, open the app yourself or the site from a bookmark you saved earlier, and look for the message there.

If Revolut needs something from you, it will be visible when you log in. This single habit defeats nearly every scenario in the previous section.

Protect the phone number. It is the reset channel for most of your accounts, and it is in the file.

Ask your carrier for a port-out PIN or SIM lock. Move two-factor codes off SMS and into an authenticator app or hardware key wherever the service allows.

Check the address before you send. The scenario that moves crypto is the “secure wallet.” Before sending funds to any address given to you by someone else, look at it.

SimpleSwap’s Address Check, available to registered users in the Customer Account, screens a wallet address through third-party services and returns a risk level with the connections it found.

It is context rather than a verdict: it will not catch every bad address, and it does not replace asking who is requesting the transfer and why.

But an address that comes back with a high risk level is a conversation you can end.

Read the map before you need it. The patterns above are covered in SimpleSwap’s Safety Academy and in the Know the Scam series.

They are far more useful to read in advance than to look up after a message has already landed.

Your money, your responsibility

None of the above depends on what Revolut does next. That is the uncomfortable part of this story and also the useful one.

Britain’s Information Commissioner’s Office has said it is investigating after Revolut reported the incident to it, and the eventual account of what happened may differ in detail from what is public today.

The files, meanwhile, are already out, and no company can recall them.

What remains in your control is what an accurate detail is worth to a stranger who has it.

Every scam we have written about in this series runs on borrowed credibility, and leaked data is how that credibility is bought.

The next message that arrives, knowing your correct name and your last transaction, is evidence that a file has leaked somewhere. It is not evidence of who sent it. Holding that distinction is most of the work.

This article is for educational purposes only and is not financial or security advice. Tools and services named here are examples, not endorsements. SimpleSwap’s only official domain is simpleswap.io

Information as of September 15, 2026. The story is still developing, and figures, timelines, and official statements below may change.

The post Revolut data leak: why the next scam may know your name appeared first on Invezz

You may also like