An attacker posed as a government agency, and Revolut handed over customer data
Revolut has confirmed that it shared customer data in response to fake official information requests sent by a third party using a real government agency's email domain, TechCrunch reported on September 12, 2026. The leaked data reportedly includes identity details, KYC documents and transaction histories. The number of affected customers was not disclosed; the company says systems and customer funds are unaffected. The Register reports a 10,000 Bitcoin ransom demand.
The attacker wrote like a government agency, and Revolut shared the data
According to TechCrunch's September 12, 2026 report, Revolut confirmed that it shared customer data in response to fake official information requests sent by a third party using a real government agency's email domain. In its statement to The Register, the company described the incident as a sophisticated external impersonation scam: the attacker sent information requests from an email address on a legitimate government agency domain. Crypto and blockchain security researcher ZachXBT shared the notifications Revolut had sent to customers on September 12, writing that the attack was targeted at high-net-worth users. Revolut's response has four parts: the fake email address was blocked as soon as it was detected, affected customers were contacted directly, the impersonated agency and law enforcement were informed, and data protection and financial regulators were notified. The company's official line to both outlets is the same: "Revolut systems and customer funds are unaffected". The difference from other breach stories: the data did not leave through an intrusion, the company shared it.
What leaked: ID copies, selfies, IBANs and full transaction histories
Per the notifications cited by TechCrunch and The Register, the shared data is wide-ranging: full names, dates of birth, postal and email addresses, phone numbers and occupation. Then KYC documents, meaning passport or driving licence copies, and verification selfies; account statements and IBANs, withdrawal records, full transaction histories and Bitcoin transaction details. One nuance: TechCrunch reports selfies, statements and transaction histories as possibly leaked rather than confirmed, while The Register bases these items on the customer notifications ZachXBT shared. The number of affected customers was not disclosed: a Revolut spokesperson told TechCrunch it was limited, and The Register was told a small proportion of customers was affected. The name and country of the impersonated agency, the market involved and the spokesperson's name were not shared either. The ransom side appears only in The Register: the perpetrators reportedly demanded 10,000 Bitcoin, more than 782 million dollars, shared fragments of data belonging to high-profile individuals in Telegram groups and threatened daily leaks. Revolut declined to comment on the ransom claims.
Why it matters: the systems held, the procedure did not
Revolut is not a small company: more than 80 million retail customers according to both outlets, more than 800,000 business customers according to The Register and operations in more than 30 countries, with recent expansion in India, Mexico, France and the UAE. It holds banking licences in France and the United Kingdom and received approval for its UK bank launch in March 2026; according to TechCrunch, the OCC granted conditional approval for a US bank licence in September 2026, with a launch expected in the first half of 2027. Its private valuation in November 2025 was 75 billion dollars, and The Register puts the IPO target after 2028 at a 200 billion dollar valuation. What makes the incident important is that a company of this scale lost data without its systems being breached. By Revolut's own account the systems were unaffected; the data left through the answer to an impersonated official request, not through a vulnerability. An email from a real agency domain passes most technical filters and lands on a human decision. The sources leave open the perpetrators' identity, a root cause analysis, the date of discovery and whether the ransom was paid.
What it means for businesses in Türkiye: even official-looking requests need verification
First the boundary: neither source mentions Türkiye or any other region, and the country of the impersonated agency was not disclosed. The sources say nothing about any link to Türkiye, but the mechanism applies directly to every business in Türkiye. Any company holding customer identity data under KVKK, such as e-commerce sites and fintechs storing ID copies, selfies, statements or address details, is exposed to social engineering built on a fake official letter, a prosecutor or police request or a ministry email. The Revolut lesson: a request from a real agency domain is not enough assurance on its own; a callback to the agency's known number or a written verification procedure is essential. The second lesson is data minimisation: collecting only the KYC data that is needed and limiting retention shrinks the impact of a leak. The third is the notification duty: the notifications Revolut made to data protection and financial regulators are equally mandatory in Türkiye, where a KVKK data breach notification must be filed within 72 hours.
The UNALSOFT view
What broke here was not technology but a decision in someone's inbox. In our E-Commerce Panel projects we recommend three things to clients for identity and order data: collect the minimum and do not store ID documents or selfies unless required; define a written verification step in advance for every official-looking data request and call the agency's known number, not the one in the email; decide today who runs the 72-hour notification flow after a breach. A fintech with 80 million customers makes the news when it skips one of these steps; a small business quietly loses customers.
Want to see how well your customer data is protected against fake official requests?
Let's look together at what data you hold, who can access it and how a request gets verified when it arrives. A short conversation is enough to start.