Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks
Overview
Revolut has confirmed a significant data breach involving sensitive customer information, including KYC documents, selfies, and Bitcoin transaction histories. This incident occurred after fraudsters sent a fake email that appeared to be from a legitimate government agency, and it successfully passed the company's security checks. The breach was disclosed on September 12, 2026, raising concerns about the effectiveness of Revolut's verification processes. Customers affected by this breach may face risks such as identity theft and financial fraud. This incident serves as a reminder for companies to bolster their security measures against social engineering attacks that exploit legitimate-looking communications.
Key Takeaways
- Affected Systems: Revolut customer KYC data, selfies, Bitcoin transaction histories
- Action Required: Revolut needs to enhance its email verification processes and user education on phishing attacks.
- Timeline: Disclosed on September 12, 2026
Original Article Summary
Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s […]
Impact
Revolut customer KYC data, selfies, Bitcoin transaction histories
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on September 12, 2026
Remediation
Revolut needs to enhance its email verification processes and user education on phishing attacks.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Data Breach.