Revolut data breach 2026: ID documents leaked after fake government emails
If you are a customer of Revolut, here’s what is being claimed, and what it would mean for you.
Revolut confirmed in September 2026 that it sent some customers’ identity documents, home addresses and contact details to scammers who emailed from a real government-agency address. A limited number of people were affected; Revolut says it contacted them directly and that customer funds were not taken.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Revolut customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On 11 September 2026, warning emails from Revolut to some of its customers began circulating. The next day, Revolut confirmed to TechCrunch and Reuters what those emails said: the company had sent personal records to an outsider who emailed from a real government-agency address. Revolut had treated the messages as genuine official requests.
It says only a limited number of customers were involved and that it contacted them directly. It has not published how many people that is, which country they were in, or which agency was impersonated. After spotting the scam, Revolut blocked the address and told the real agency, the police, and financial and data-protection regulators. It says its own systems were not broken into and that customer money was not taken.
Your money was not taken. Your identity file was handed over.
Most write-ups of this story lead with the same two points Revolut wants you to hear: this was a fake government request, and no one stole money from Revolut accounts. Both of those are true. They are also not the part that changes your week.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
The outsider did not need to crack Revolut’s computers. Revolut sent the files, believing it was complying with an official demand. What left the company, according to the emails TechCrunch reviewed, was the packet other institutions use to accept you as you: date of birth, home address, email, phone number, and copies of passports and driving licences. Those emails also warned that verification selfies, account statements and transaction histories may have been included.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
That is not a password leak. You cannot issue yourself a new date of birth, and a copy of a passport does not become harmless because the bank app still shows the right balance. Someone now has, for at least some customers, the same documents you would present to open an account, rent a flat, or prove your name — sitting next to the address where you live.
How those customers were chosen is not confirmed, and neither is the size of the group. What is confirmed is what kind of file moved: identity paperwork, not a drained wallet.
What to actually expect
- Revolut says it has already emailed the people in this incident. There is no public list, and nothing on the internet can look up whether you were one of them. If a message about this did arrive, treat it as a warning — not as a reason to send more documents.
- In the near term, the useful fraud is not emptying your Revolut balance. It is someone else using a copy of your ID and address to open accounts, order credit, or pass identity checks in your name.
- You may get calls, texts or emails that already know your address, your date of birth, or that you bank with Revolut, and that offer to “help” with the leak. Treat unexpected contact as fake, even if it uses a government or Revolut name.
- If your notice mentioned statements or transaction history, those details can be used to sound like genuine support staff. Revolut will not ask you, out of the blue, to confirm a payment or to upload your passport again to “secure” this event.
What you can and cannot fix
The copies Revolut sent cannot be taken back. If a passport, driving licence, selfie, date of birth or home address was in that file, it is out. No bank, regulator or cleanup service can un-send it, and anyone who promises to delete it from the scammer’s hands is not telling you the truth.
What still helps is making that file harder to use, and cutting the extra personal detail that turns one leaked record into a full picture of your life.
- Do not send new copies of your ID, a selfie, or statements to anyone who contacts you about this. If you need to speak to Revolut, start from the app you already use or a number printed on a card you already own.
- Watch for credit, accounts, phone-number changes and official letters you did not ask for. That is the usual next step when copies of passports and licences have left a company.
- Assume the email address and phone number in the file will be used to reach you with fake “official” messages about this incident. Do not use links or numbers from those messages.
- Reduce what people-search and directory sites publish about you. A leaked Revolut record is a bundle of facts sitting on its own. It becomes much more dangerous when those sites bolt on relatives, extra phone numbers, employers and previous addresses. Unlike the stolen copies, those listings can often actually be taken down, which is why that step is worth doing even though it does not reverse the leak.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Revolut.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
- Report the passport number. A compromised passport number can be reported to the US State Department, which will flag it. Replacing it is neither quick nor free, so report it before you need to travel.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
PayPal SSN Exposure Lasting Six Months — February 2026
A code change at PayPal allowed unauthorized access to Social Security Numbers and account details f…
Malaysia National Registration Department 22.5 Million — May 2022
A breach of Malaysia's National Registration Department exposed ~22.5 million citizen records, inclu…