September 14, 2026, 3:50 pm | Read time: 3 minutes
The British company Revolut has fallen victim to identity fraud. Attackers allegedly posed as employees of a legitimate authority and submitted information requests to the company. Revolut apparently considered the requests legitimate and reportedly released sensitive, personal customer data. Affected data includes ID documents, verification selfies, and transaction data.
What is known about the incident
According to Revolut, which officially confirmed the incident to media outlets, the company was not the victim of a classic cyberattack. Instead, an unauthorized third party sent an email using a government domain, posing as an authorized contact. The request appeared credible to the fintech company.
It was only later discovered that the email did not originate from an authorized person. Revolut describes the incident as a “sophisticated fraud through identity theft.”
What data is affected?
The nature of the potentially disclosed information is particularly critical. According to a report by the online magazine “TechCrunch,” the following data may be affected:
- Identity and contact data, including birth dates
- Postal and email addresses
- Phone numbers
- Copies of ID documents, including passports and driver’s licenses
- Verification selfies
- Bank statements
- Transaction histories
As a Revolut user reported on X on September 11, IBANs, withdrawal receipts, and complete transaction histories, including Bitcoin transactions, were also disclosed. However, the company emphasizes that its own systems were not compromised at any time. Customer funds were also reportedly not affected by the incident.
Many questions remain unanswered
Revolut mentions a “limited” number of affected customers. However, a specific number has not yet been disclosed. It is also unclear from which countries the affected individuals come. The bank claims to have over 80 million customers in more than 30 countries.
As Revolut explained to TechCrunch, the company responded immediately after discovering the incident. The email was blocked immediately after the incident was discovered, and the affected authority was informed. Law enforcement agencies, as well as data protection and financial supervisory authorities, have also been involved.
Protect Yourself From Identity Theft With These Tips
Attention, Savings Bank Customers: This Email Could Empty Your Account
What rights do those affected have
Even though no passwords or customer funds are believed to have been leaked, the potentially disclosed information is extremely sensitive. With copies of IDs, personal data, and account information, targeted fraud attempts can be prepared. Affected individuals should therefore be particularly vigilant for unusual emails, SMS, or calls in the coming weeks.
Also of interest: Klarna to link credit card to paid subscription in the future
For customers, the General Data Protection Regulation (GDPR) provides several rights. According to “Netz Trends,” under Article 15 of the GDPR, individuals can request information about which personal data is affected and to whom it may have been disclosed. Such a request can be directed to Revolut Bank UAB. Additionally, under Article 77 of the GDPR, there is the option to file a complaint with the data protection authority at one’s place of residence, which would then be forwarded to the authority responsible for Revolut in Lithuania.
Possible compensation
Furthermore, there may be potential claims for compensation. Article 82 of the GDPR provides for compensation for material and non-material damages. Whether such a claim actually exists depends on the individual case.
It also remains open whether Revolut has complied with all legal reporting obligations. Under Article 33 of the GDPR, data breaches must generally be reported to the relevant supervisory authority within 72 hours.