Revolut Discloses Data Breach Exposing Financial Information and Passport Data
Threat actor impersonated a government agency to obtain customer data

Key Takeaways
- Revolut confirmed a data breach involving customer financial and passport data.
- A threat actor impersonated a government agency to obtain the information.
- The number of affected customers has not been specified.
- Affected customers are being notified and advised to remain vigilant.
- The incident highlights the risk of social engineering and impersonation attacks targeting financial institutions.
Quick answers
- What happened?
- Revolut has disclosed a data breach in which customer financial information and passport data was shared with a threat actor who impersonated a government agency. The exact number of affected customers remains undisclosed. The incident was reported by BleepingComputer on 2026-09-14.
- What should defenders do?
- Affected customers should monitor financial accounts for unusual activity, enable multi-factor authentication where available, and be alert to phishing attempts. Revolut is likely to enhance verification procedures and customer notification processes.
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. According to initial reporting, the threat actor obtained customer financial information and passport data through deception, posing as a government entity. The scope of the compromise, including the specific number of affected individuals and the precise methods used in the impersonation, is still under investigation. Revolut has stated that it is notifying affected customers and reviewing its internal verification procedures. The company emphasized that it is working with relevant authorities to address the incident. No patch is applicable, as this incident involves unauthorized data sharing rather than a software vulnerability.
Security Details
Threat actor impersonated a government agency to obtain customer financial information and passport data from Revolut. The specific attack vector and full scope of data compromised are under investigation.
Mitigation
Affected customers should monitor financial accounts for unusual activity, enable multi-factor authentication where available, and be alert to phishing attempts. Revolut is likely to enhance verification procedures and customer notification processes.
Sources
BleepingComputer
Revolut discloses data breach exposing financial info, passports
Sep 14, 2026 · 08:48
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



