Insights

The Revolut Data Breach: What Happened, What It Means for You, and How to Protect Your Rights

Legal analysis and client guidelines for protecting the rights and mitigating risks Summary In September 2026, Revolut customers began receiving a breach notification unlike…

The Revolut Data Breach: What Happened, What It Means for You, and How to Protect Your Rights

Legal analysis and client guidelines for protecting the rights and mitigating risks

Summary

In September 2026, Revolut customers began receiving a breach notification unlike any the company has issued before. It did not describe a hacked server or a stolen password. It described something more unsettling: Revolut itself handed over a package of customer data – passports, driver’s licences, onboarding selfies, IBANs, account histories, and complete Bitcoin transaction records – to a party that turned out not to be who it claimed to be.

Within days, the incident escalated further. A threat actor came forward claiming to hold this data and threatening to release progressively more of it, including information belonging to high-profile customers, unless Revolut pays. As of this writing, the scale of the breach, the identity of the government body impersonated, and the full extent of what has actually been published remain unconfirmed — but the categories of data described in Revolut’s own notification are specific, internally consistent with its product range, and more sensitive than anything exposed in its previous incidents.

If you are a Revolut customer – and particularly if you hold or have held cryptocurrency through the platform – this is not a breach notice to file away. Below, we explain what happened, what the realistic risks are, what you should do in the next 90 days, and what legal remedies are available to you, individually or as part of a coordinated group action. DRC is already assessing individual and collective claims arising from this incident — see “How DRC Can Help” below for how to get support with your specific situation.


What Happened

According to Revolut’s own communication to affected customers, the company received what appeared to be a legitimate request for customer information from a government authority. The request came from an email account operating within that authority’s genuine domain infrastructure and carried valid domain authentication credentials. On the strength of that authentication, Revolut’s compliance function treated the request as authentic and disclosed customer data in response.

It later emerged that the requesting account was not authorised. Someone had gained control of, or created, a mailbox inside a real government domain and used it to submit a fraudulent request. Revolut states that once it became aware of the issue, it independently contacted the relevant authority to verify the request, blocked the account across its systems, notified regulators, and applied protective measures for affected customers.

Four categories of data were disclosed:

  • Identity details — full name, date of birth, occupation
  • Contact details — postal address, email address, telephone number
  • Identity verification documents — passport or driver’s licence copies, plus the facial verification selfie submitted at onboarding
  • Financial data — IBAN, account status and opening date, crypto wallet reference number, withdrawal records, and complete transaction history, including Bitcoin

Revolut has stated that “biometric facial telemetry” – the underlying mathematical data a verification system derives from a face scan – was not compromised, only the raw photographic image. That distinction matters legally, and we address it below.

Days after the initial notification, a threat actor claiming responsibility said further data would be released incrementally unless Revolut met payment demands, and suggested that samples belonging to high-net-worth customers would be among the disclosures. None of these claims has been independently verified, and the existence of an extortion demand does not by itself confirm the scope or authenticity of what has been obtained. What is confirmed is that Revolut’s own notification describes a genuine, sensitive data disclosure – the open question is how far it has spread since.

This is also not an isolated event. Revolut disclosed a breach affecting roughly 50,000 customers in 2022 following a phished employee credential. In early 2026, a customer alleged that a former employee threatened to leak their KYC file unless paid in cryptocurrency. In mid-2026, a forum listing claimed 75 million records were for sale (which Revolut disputed). This incident is the most severe in that pattern, both in the sensitivity of the data involved and in the mechanism — a trusted process, not a technical vulnerability, was the point of failure.


Why This Is Different From “Just Another Breach”

Most data breaches involve an intrusion: a stolen credential, an exploited vulnerability, unauthorised access. Detection systems are built to catch exactly that. This incident did not involve a hack in the conventional sense. Every step in the chain — the login, the internal request, the data export — was, from a systems perspective, legitimate. The failure was procedural: a formally authenticated request was treated as sufficient proof of authority, without independent, out-of-band verification.

That distinction should inform how seriously you treat this notice. A compromised password can be reset. A compromised identity document and a matched biometric photograph cannot be “rotated.” Once your passport, your face, your address, and your financial history are outside your bank’s control, the exposure does not expire.


What the Risks Actually Are

1. Identity theft and synthetic identity fraud

Your name, date of birth, occupation, address, and a government-issued photo ID together form a near-complete forgery kit. This data can be used to open accounts, apply for credit, or pass identity checks at other institutions in your name.

2. Biometric and deepfake exposure

Revolut’s notice draws a legal line between a raw photograph and a “biometric template.” That line is real under data protection law, but thin in practice. A leaked selfie combined with a matched passport scan is exactly the input criminal tooling uses to defeat liveness checks and identity verification systems elsewhere — including at other financial institutions and exchanges.

3. Targeted phishing, vishing, and account takeover

Your real account attributes – IBAN, balance history, account opening date – let a fraudster sound credible when contacting you or when contacting your bank pretending to be you. Prior Revolut incidents show this follow-on phishing typically extends beyond the directly affected customer group.

4. Deanonymisation of cryptocurrency holdings

This is the risk specific to this breach that deserves the most attention. A blockchain ledger is public, but ownership is pseudonymous — until an identity is attached to a wallet. A leaked KYC file that ties your verified name and address to your wallet reference number and full transaction history does exactly that, permanently. Blockchain records are append-only: the link, once established, extends forward through every future transaction via standard chain-analysis clustering. For holders of significant positions, this converts an abstract privacy concern into a concrete targeting list – for extortion, for “dusting” and phishing campaigns aimed at known holders, and in the more serious cases already reported involving Revolut customers, for direct extortion demands tied to threats of exposing KYC files to family members or associates.

5. Physical safety risk

Where deanonymised crypto holdings are combined with a known home address, the risk moves beyond financial fraud. This combination is precisely what is used to identify targets for coercion, burglary, or physical extortion – a risk that regulators and courts increasingly recognise as a legitimate head of harm distinct from ordinary financial loss.

6. Elevated risk for politically or reputationally sensitive customers

Customers whose financial histories could reveal donations, affiliations, or activity they have reason to keep confidential — including support for civil society, human rights, or opposition-linked organisations in jurisdictions where such activity is criminalised — face a materially higher category of risk if their data reaches a party able to act against them on that basis. If you fall into this category, treat this notification as urgent and seek legal and security advice without delay.

If any of the above applies to you, DRC can help you assess your specific exposure – including cases involving cryptocurrency deanonymisation or politically sensitive financial activity – and advise on both protective steps and legal claims before you take any other action.


What You Should Do Now

Treat the coming months as a period of elevated exposure, not a one-off notice to acknowledge and forget.

  1. Verify independently, trust nothing inbound. Revolut will not contact you asking for codes, passwords, or approvals. If anyone does — by phone, email, or message — assume it is an attack, even if they appear to know real details about your account. Confirm anything through the official app or a number you look up yourself.
  1. Harden your accounts. Move to phishing-resistant two-factor authentication (a passkey or hardware key, not SMS) on your email and financial accounts. Review linked devices and active sessions. Enable app-level biometric locks where available.
  1. Register for fraud and identity-theft monitoring. Depending on your jurisdiction, this may mean protective registration with a fraud-prevention body, a credit freeze with credit bureaus, or enrolment in identity-monitoring services. Your identity documents are now, effectively, a pre-filled application kit for someone else.
  1. Monitor your accounts and statements actively. Set transaction alerts. Scrutinise any unfamiliar direct debit mandates — unauthorised debits typically carry longer claim windows than disputed-but-authorised ones, so time limits matter and you should not delay reporting anything irregular.
  1. Treat your cryptocurrency exposure as attributed from this point forward. Use fresh receiving addresses going forward, do not respond to “wallet verification” messages, and avoid discussing your holdings in any channel that could link back to your identity. If you hold a significant position, review your personal security posture on the assumption that your approximate balance is known to someone outside your control.
  1. Watch for identity misuse over the long term, not just this week. Fraudulent credit applications, unexpected collection notices, or tax correspondence you don’t recognise are the delayed indicators of document fraud. Check your credit file periodically for at least the next year.
  1. Preserve everything. Keep the original breach notification, screenshot any suspicious contact, and log dates and details. This record is what will support both a regulatory complaint and any civil claim.

DRC can guide you through this checklist against your specific circumstances, and help you build and preserve the evidentiary record a future claim will rely on — contact us before, not after, you take further action.


The Legal Picture: Regulatory Exposure and Your Right to Compensation

This is not a case where “we were deceived” ends the analysis. Under the General Data Protection Regulation, the obligation on a data controller – here, Revolut – is to have appropriate technical and organisational measures in place to verify the authenticity of requests before disclosing customer data, particularly requests of this sensitivity and scale. Regulatory precedent involving other financial institutions has consistently rejected “we were the victims of a sophisticated deception” as a defence that reduces liability. Formal domain authentication is not, on its own, an adequate substitute for independent verification through a pre-established channel.

Several provisions are likely to be central to any regulatory or civil assessment:

  • Article 5(1)(f) and Article 32 — the core question of whether adequate technical and organisational security measures, including a genuine multi-channel verification process for third-party data requests, were in place.
  • Article 25 — “data protection by design,” and specifically why data of this sensitivity, including full on-chain transaction history, was held in a form that allowed it to be disclosed as a single package in response to one request.
  • Articles 33 and 34 — the obligations to notify the supervisory authority within 72 hours and to notify affected individuals directly where the risk to their rights is high.
  • Article 9 — the special-category regime for biometric data. Revolut’s assertion that only a raw image, not a derived biometric template, was exposed is a legally significant distinction, but not necessarily a complete shield: regulators assess risk by what the data enables an attacker to do, not merely by its technical classification.

For firms operating in the EEA on a Lithuanian licence, the Lithuanian State Data Protection Inspectorate is the relevant lead supervisory authority, alongside obligations under the Digital Operational Resilience Act (DORA) concerning the governance of operational risk from exactly this kind of social-engineering failure. UK customers additionally fall under the UK GDPR and ICO oversight. Theoretical regulatory penalties can reach up to 4% of global annual turnover or €20 million, whichever is higher – but for affected individuals, the more immediately relevant route is direct compensation.

Your right to claim compensation

Under Article 82 GDPR, you are entitled to seek compensation for both material and non-material damage arising from an infringement — this includes not only direct financial loss, but distress, anxiety, and the loss of control over your own sensitive data, including your biometric image and your financial and cryptocurrency history. You also have the right under Article 77 to lodge a complaint directly with your supervisory authority.

Critically, you do not need to have already suffered fraud to have a claim. The exposure of identity documents, a facial image, and a deanonymised financial history is, in itself, a recognised form of compensable harm in a growing body of data-protection litigation across Europe — and the more sensitive the data category, the stronger that claim tends to be.

DRC can evaluate whether your case meets this threshold and calculate a realistic claim value based on the specific data categories that applied to you.


How DRC Can Help

We act for individuals affected by financial-sector data breaches, and we are actively building a coordinated response to this incident on behalf of Revolut customers.

If you received a breach notification from Revolut, or believe your data may have been affected, we can help you:

Collective actions of this kind are becoming an increasingly effective route against financial institutions that fail in their data protection obligations, precisely because incidents like this one rarely affect a single customer. If you were notified, it is highly likely others in your position were as well — and a coordinated claim strengthens the position of every participant.

If you are a Revolut customer, particularly one who holds or has held meaningful cryptocurrency balances through the platform, we recommend you speak with a lawyer before taking any other action. Time limits apply to both regulatory complaints and civil claims, and the steps you take now – including what you say to Revolut, and what evidence you preserve — can materially affect the strength of your case later.


This article is provided for general informational purposes and does not constitute legal advice. Facts concerning the ongoing Revolut incident, including the scope of data affected and the authenticity of claims made by any threat actor, remain partially unconfirmed at the time of writing and may be updated as further information becomes available. If you believe you have been affected, we recommend seeking individual legal advice specific to your circumstances.

databreach gdpr revolut

Related topics

Contact us

Use the form below to outline your legal matter.
We will review your request and respond promptly.
All information is treated as confidential
Alternative contact options
Please note that messenger communication is not intended for sharing sensitive or confidential information