Somewhere on Friday a man opened an email from Revolut and read that the bank had given a copy of his passport, his home address, his phone number and his complete transaction history, Bitcoin included, to someone pretending to be a government agency. He has not lost a penny. He has lost something harder to replace: whoever holds that file now knows how much he has, where it sits, and exactly what a message from his bank looks like.
Confirmation: confirmed by the company. Revolut sent notices to affected customers on 11 September 2026, and its statement to reporters describes “a sophisticated external impersonation scam.” Revolut has not said how many customers are affected.
What happened
Revolut disclosed customer records to an unauthorised third party who submitted fraudulent requests for information from a legitimate government agency’s email domain, the company confirmed on 12 September 2026. Banks receive data requests from police, tax authorities and regulators every day, and they answer them. This one came from a real government address, and Revolut answered it before finding out that nobody at the agency had sent it.
The timeline, from TechCrunch, The Block and CoinDesk:
- Before 11 September. A request for customer records arrived at Revolut from an email address on a genuine government agency domain. It passed the bank’s checks and Revolut released the records it asked for.
- After the release. Revolut contacted the agency separately, learned the request was fraudulent, and blocked the sending address. In its words: “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
- 11 September. Affected customers received notification emails. Revolut says it has alerted the agency, law enforcement, data protection authorities and financial regulators.
- 12 September. Revolut confirmed the incident to reporters, said a “limited” number of customers were affected, and said its systems and customer funds were not touched. It declined to give a number or say which markets are involved.
Crypto investigator ZachXBT, who reviewed the notices, said the incident “seems to have been targeted at high net worth users.” The Block reported that former Mt. Gox chief executive Mark Karpelès confirmed he was among those notified. Revolut has not named the agency whose domain was used or said which country it is in.
Update, 14 September 2026. Revolut’s fuller statement, reported by BleepingComputer and SecurityWeek, says the fraudulent emails carried “valid domain authentication credentials” and that the records were released “under the reasonable belief that it was an authentic government agency request.” The company added occupation to the list of identity details in the notices, and again declined to give a number, saying “a limited number of customers” were affected. It is Revolut’s second disclosed breach: in September 2022 the personal, contact and financial data of 50,150 customers was exposed in a separate incident. The agency and the country are still unnamed.
What was exposed
According to Revolut’s own notice, the released records include identity and contact details, copies of identity documents and full account histories. The list, as customers reported it:
- Name, date of birth, home address, email address and phone number. Everything a scammer needs to pass as you, or to pass as your bank when they call you.
- Copies of your passport or driving licence, and possibly the verification selfie. The documents you used to open the account. A real ID image with a matching face is what defeats identity checks at other companies.
- Account statements, IBANs and withdrawal records. Your balance, your income pattern, and where your money goes.
- Transaction histories, including Bitcoin transactions. For a crypto holder this is the dangerous one: it tells a criminal that you are worth targeting, and it may link your name to on-chain addresses that were previously anonymous.
No passwords were in the release, and Revolut says no account was accessed. The risk here is not that someone signs in as you. It is that someone who knows your balance, your last five transactions and what your ID looks like sends you an email that is very hard to doubt.
What to do now
Most of this has nothing to do with OptMsg, and the first two steps take ten minutes.
1. Treat every “Revolut” email, text and call as suspect for the next few months. The follow-up will cite real transactions because the scammer has them. “We detected unusual activity on your account,” “confirm your identity after the recent security incident,” “your funds have been moved to a safe account.” Revolut will not ask you to move money, share a code or install anything. Open the app yourself; do not follow a link. 2. Lock in-app security. Turn on a passkey or biometric login in the Revolut app, set a separate PIN for card payments, and turn on transaction notifications so you see any movement the moment it happens. 3. Watch your phone number. A name, date of birth, address and ID copy is the kit for a SIM swap. Ask your carrier for a port-out or account PIN today. If your phone drops to “no service” without reason, call the carrier from another phone immediately. 4. If you hold crypto, assume your holdings are known. Move long-term funds to a wallet not linked to the exchange account, do not discuss balances with anyone who contacts you, and be alert to in-person approaches as well as online ones. 5. Report your ID documents as compromised. In the UK, that is Action Fraud and a note to HM Passport Office; in the EU, your national police and the issuing authority. Ask whether a replacement document with a new number is possible. Put a fraud alert or a credit freeze on your file with the credit agencies in your country. 6. Turn on the strongest sign-in each account offers, starting with your email account. It is the reset route into everything else. A passkey where available, an authenticator app otherwise, and a password manager so each account has its own password. 7. Ask Revolut what was released about you. Under GDPR you can request the exact records. Keep the reply; it is the evidence if fraud follows.
How OptMsg changes this exposure
Honestly, and at its real size: OptMsg would not have prevented this breach. It happened inside Revolut’s compliance process, answering a request that looked like the law asking. Your email address was in the file, and so was enough to write you a very convincing message. What an opt-in inbox changes is where that message lands.
Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the “confirm your identity after the recent incident” email, sent from a look-alike domain the real Revolut has not used, lands in Trash, where you are not reading it under time pressure with your real balance quoted back at you. The genuine Revolut reaches your Inbox once you approve it as a sender. Only people you approve can reach your inbox. Everyone else goes to Trash. And if a message in Trash comes from a sender many other OptMsg users have opted in to, you get a push alert, so a genuine notice is not lost.
The password point is smaller here than usual, because no password leaked. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. If this file is later matched to a password from an older breach, the pair opens nothing at OptMsg, and the reset route into your other accounts stays shut while you deal with the documents themselves.
What that does not cover: a phone call from “Revolut’s fraud team” that knows your last transaction, a text to your number, a SIM swap at your carrier, a phishing page you open yourself, or someone with your unlocked phone. Those are the steps above, and the first one does most of the work.
If you want the next breach’s follow-up mail to land in Trash instead of in front of you, see how Security First works, or read why your inbox should not care about a leaked password.
Ready for an inbox that stays quiet after a breach? Create Your Account.
Your Inbox. Your Rules.
Frequently asked questions
How do I know if I am in the Revolut data breach? Revolut emailed the affected customers directly on 11 September 2026. If you did not receive a notice, Revolut says you are not affected. There is no public lookup, and the released data is not on Have I Been Pwned.
What was stolen in the Revolut breach? According to the customer notice: names, dates of birth, postal and email addresses, phone numbers, copies of passports or driving licences, possibly verification selfies, account statements, IBANs and transaction histories including Bitcoin transactions. No passwords, and Revolut says no accounts were accessed.
Was Revolut hacked? Not in the usual sense. Nobody broke into its systems. Someone sent a fraudulent records request from a genuine government agency’s email domain, and Revolut released the records before discovering the request was fake.
Is my money safe? Revolut says customer funds and its systems were unaffected. The risk is what comes next: phishing and phone scams that quote your real transactions, and identity fraud using your ID document copy.
Would OptMsg have stopped this? No. The breach happened at Revolut. What OptMsg changes is the aftermath: mail from a sender you have not approved goes to Trash rather than your Inbox, and there is no password on an OptMsg account for a leaked credential to match.
Sources
- TechCrunch: Revolut confirms customer data breach through fake government requests — 12 September 2026
- The Block: Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov’t domain — 12 September 2026
- CoinDesk: Bitcoin activity, passports exposed after Revolut falls for fake government request — 12 September 2026