Legal analysis and client guidelines for protecting the rights and mitigating risks Summary In September 2026, Revolut customers began receiving a breach notification unlike…
Legal analysis and client guidelines for protecting the rights and mitigating risks
In September 2026, Revolut customers began receiving a breach notification unlike any the company has issued before. It did not describe a hacked server or a stolen password. It described something more unsettling: Revolut itself handed over a package of customer data – passports, driver’s licences, onboarding selfies, IBANs, account histories, and complete Bitcoin transaction records – to a party that turned out not to be who it claimed to be.
Within days, the incident escalated further. A threat actor came forward claiming to hold this data and threatening to release progressively more of it, including information belonging to high-profile customers, unless Revolut pays. As of this writing, the scale of the breach, the identity of the government body impersonated, and the full extent of what has actually been published remain unconfirmed — but the categories of data described in Revolut’s own notification are specific, internally consistent with its product range, and more sensitive than anything exposed in its previous incidents.
If you are a Revolut customer – and particularly if you hold or have held cryptocurrency through the platform – this is not a breach notice to file away. Below, we explain what happened, what the realistic risks are, what you should do in the next 90 days, and what legal remedies are available to you, individually or as part of a coordinated group action. DRC is already assessing individual and collective claims arising from this incident — see “How DRC Can Help” below for how to get support with your specific situation.
According to Revolut’s own communication to affected customers, the company received what appeared to be a legitimate request for customer information from a government authority. The request came from an email account operating within that authority’s genuine domain infrastructure and carried valid domain authentication credentials. On the strength of that authentication, Revolut’s compliance function treated the request as authentic and disclosed customer data in response.
It later emerged that the requesting account was not authorised. Someone had gained control of, or created, a mailbox inside a real government domain and used it to submit a fraudulent request. Revolut states that once it became aware of the issue, it independently contacted the relevant authority to verify the request, blocked the account across its systems, notified regulators, and applied protective measures for affected customers.
Four categories of data were disclosed:
Revolut has stated that “biometric facial telemetry” – the underlying mathematical data a verification system derives from a face scan – was not compromised, only the raw photographic image. That distinction matters legally, and we address it below.
Days after the initial notification, a threat actor claiming responsibility said further data would be released incrementally unless Revolut met payment demands, and suggested that samples belonging to high-net-worth customers would be among the disclosures. None of these claims has been independently verified, and the existence of an extortion demand does not by itself confirm the scope or authenticity of what has been obtained. What is confirmed is that Revolut’s own notification describes a genuine, sensitive data disclosure – the open question is how far it has spread since.
This is also not an isolated event. Revolut disclosed a breach affecting roughly 50,000 customers in 2022 following a phished employee credential. In early 2026, a customer alleged that a former employee threatened to leak their KYC file unless paid in cryptocurrency. In mid-2026, a forum listing claimed 75 million records were for sale (which Revolut disputed). This incident is the most severe in that pattern, both in the sensitivity of the data involved and in the mechanism — a trusted process, not a technical vulnerability, was the point of failure.
Most data breaches involve an intrusion: a stolen credential, an exploited vulnerability, unauthorised access. Detection systems are built to catch exactly that. This incident did not involve a hack in the conventional sense. Every step in the chain — the login, the internal request, the data export — was, from a systems perspective, legitimate. The failure was procedural: a formally authenticated request was treated as sufficient proof of authority, without independent, out-of-band verification.
That distinction should inform how seriously you treat this notice. A compromised password can be reset. A compromised identity document and a matched biometric photograph cannot be “rotated.” Once your passport, your face, your address, and your financial history are outside your bank’s control, the exposure does not expire.
Your name, date of birth, occupation, address, and a government-issued photo ID together form a near-complete forgery kit. This data can be used to open accounts, apply for credit, or pass identity checks at other institutions in your name.
Revolut’s notice draws a legal line between a raw photograph and a “biometric template.” That line is real under data protection law, but thin in practice. A leaked selfie combined with a matched passport scan is exactly the input criminal tooling uses to defeat liveness checks and identity verification systems elsewhere — including at other financial institutions and exchanges.
Your real account attributes – IBAN, balance history, account opening date – let a fraudster sound credible when contacting you or when contacting your bank pretending to be you. Prior Revolut incidents show this follow-on phishing typically extends beyond the directly affected customer group.
This is the risk specific to this breach that deserves the most attention. A blockchain ledger is public, but ownership is pseudonymous — until an identity is attached to a wallet. A leaked KYC file that ties your verified name and address to your wallet reference number and full transaction history does exactly that, permanently. Blockchain records are append-only: the link, once established, extends forward through every future transaction via standard chain-analysis clustering. For holders of significant positions, this converts an abstract privacy concern into a concrete targeting list – for extortion, for “dusting” and phishing campaigns aimed at known holders, and in the more serious cases already reported involving Revolut customers, for direct extortion demands tied to threats of exposing KYC files to family members or associates.
Where deanonymised crypto holdings are combined with a known home address, the risk moves beyond financial fraud. This combination is precisely what is used to identify targets for coercion, burglary, or physical extortion – a risk that regulators and courts increasingly recognise as a legitimate head of harm distinct from ordinary financial loss.
Customers whose financial histories could reveal donations, affiliations, or activity they have reason to keep confidential — including support for civil society, human rights, or opposition-linked organisations in jurisdictions where such activity is criminalised — face a materially higher category of risk if their data reaches a party able to act against them on that basis. If you fall into this category, treat this notification as urgent and seek legal and security advice without delay.
If any of the above applies to you, DRC can help you assess your specific exposure – including cases involving cryptocurrency deanonymisation or politically sensitive financial activity – and advise on both protective steps and legal claims before you take any other action.
Treat the coming months as a period of elevated exposure, not a one-off notice to acknowledge and forget.
DRC can guide you through this checklist against your specific circumstances, and help you build and preserve the evidentiary record a future claim will rely on — contact us before, not after, you take further action.
This is not a case where “we were deceived” ends the analysis. Under the General Data Protection Regulation, the obligation on a data controller – here, Revolut – is to have appropriate technical and organisational measures in place to verify the authenticity of requests before disclosing customer data, particularly requests of this sensitivity and scale. Regulatory precedent involving other financial institutions has consistently rejected “we were the victims of a sophisticated deception” as a defence that reduces liability. Formal domain authentication is not, on its own, an adequate substitute for independent verification through a pre-established channel.
Several provisions are likely to be central to any regulatory or civil assessment:
For firms operating in the EEA on a Lithuanian licence, the Lithuanian State Data Protection Inspectorate is the relevant lead supervisory authority, alongside obligations under the Digital Operational Resilience Act (DORA) concerning the governance of operational risk from exactly this kind of social-engineering failure. UK customers additionally fall under the UK GDPR and ICO oversight. Theoretical regulatory penalties can reach up to 4% of global annual turnover or €20 million, whichever is higher – but for affected individuals, the more immediately relevant route is direct compensation.
Under Article 82 GDPR, you are entitled to seek compensation for both material and non-material damage arising from an infringement — this includes not only direct financial loss, but distress, anxiety, and the loss of control over your own sensitive data, including your biometric image and your financial and cryptocurrency history. You also have the right under Article 77 to lodge a complaint directly with your supervisory authority.
Critically, you do not need to have already suffered fraud to have a claim. The exposure of identity documents, a facial image, and a deanonymised financial history is, in itself, a recognised form of compensable harm in a growing body of data-protection litigation across Europe — and the more sensitive the data category, the stronger that claim tends to be.
DRC can evaluate whether your case meets this threshold and calculate a realistic claim value based on the specific data categories that applied to you.
We act for individuals affected by financial-sector data breaches, and we are actively building a coordinated response to this incident on behalf of Revolut customers.
If you received a breach notification from Revolut, or believe your data may have been affected, we can help you:
Collective actions of this kind are becoming an increasingly effective route against financial institutions that fail in their data protection obligations, precisely because incidents like this one rarely affect a single customer. If you were notified, it is highly likely others in your position were as well — and a coordinated claim strengthens the position of every participant.
If you are a Revolut customer, particularly one who holds or has held meaningful cryptocurrency balances through the platform, we recommend you speak with a lawyer before taking any other action. Time limits apply to both regulatory complaints and civil claims, and the steps you take now – including what you say to Revolut, and what evidence you preserve — can materially affect the strength of your case later.
Contact DRC for a confidential initial consultation.
This article is provided for general informational purposes and does not constitute legal advice. Facts concerning the ongoing Revolut incident, including the scope of data affected and the authenticity of claims made by any threat actor, remain partially unconfirmed at the time of writing and may be updated as further information becomes available. If you believe you have been affected, we recommend seeking individual legal advice specific to your circumstances.
More Insights