Skip to content
Back to Blog
high severity September 12, 2026 · 4 min read Unverified claim — what this is

Revolut data breach 2026: ID documents leaked after fake government emails

If you are a customer of Revolut, here’s what is being claimed, and what it would mean for you.

Revolut confirmed in September 2026 that it sent some customers’ identity documents, home addresses and contact details to scammers who emailed from a real government-agency address. A limited number of people were affected; Revolut says it contacted them directly and that customer funds were not taken.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Revolut data breach 2026: ID documents leaked after fake government emails

On 11 September 2026, warning emails from Revolut to some of its customers began circulating. The next day, Revolut confirmed to TechCrunch and Reuters what those emails said: the company had sent personal records to an outsider who emailed from a real government-agency address. Revolut had treated the messages as genuine official requests.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

It says only a limited number of customers were involved and that it contacted them directly. It has not published how many people that is, which country they were in, or which agency was impersonated. After spotting the scam, Revolut blocked the address and told the real agency, the police, and financial and data-protection regulators. It says its own systems were not broken into and that customer money was not taken.

Your money was not taken. Your identity file was handed over.

Most write-ups of this story lead with the same two points Revolut wants you to hear: this was a fake government request, and no one stole money from Revolut accounts. Both of those are true. They are also not the part that changes your week.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • A deeper search of collected breach data — the kinds of your information it holds, where it finds you
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

The outsider did not need to crack Revolut’s computers. Revolut sent the files, believing it was complying with an official demand. What left the company, according to the emails TechCrunch reviewed, was the packet other institutions use to accept you as you: date of birth, home address, email, phone number, and copies of passports and driving licences. Those emails also warned that verification selfies, account statements and transaction histories may have been included.

That is not a password leak. You cannot issue yourself a new date of birth, and a copy of a passport does not become harmless because the bank app still shows the right balance. Someone now has, for at least some customers, the same documents you would present to open an account, rent a flat, or prove your name — sitting next to the address where you live.

How those customers were chosen is not confirmed, and neither is the size of the group. What is confirmed is what kind of file moved: identity paperwork, not a drained wallet.

What to actually expect

  • Revolut says it has already emailed the people in this incident. There is no public list, and nothing on the internet can look up whether you were one of them. If a message about this did arrive, treat it as a warning — not as a reason to send more documents.
  • In the near term, the useful fraud is not emptying your Revolut balance. It is someone else using a copy of your ID and address to open accounts, order credit, or pass identity checks in your name.
  • You may get calls, texts or emails that already know your address, your date of birth, or that you bank with Revolut, and that offer to “help” with the leak. Treat unexpected contact as fake, even if it uses a government or Revolut name.
  • If your notice mentioned statements or transaction history, those details can be used to sound like genuine support staff. Revolut will not ask you, out of the blue, to confirm a payment or to upload your passport again to “secure” this event.

What you can and cannot fix

The copies Revolut sent cannot be taken back. If a passport, driving licence, selfie, date of birth or home address was in that file, it is out. No bank, regulator or cleanup service can un-send it, and anyone who promises to delete it from the scammer’s hands is not telling you the truth.

What still helps is making that file harder to use, and cutting the extra personal detail that turns one leaked record into a full picture of your life.

  • Do not send new copies of your ID, a selfie, or statements to anyone who contacts you about this. If you need to speak to Revolut, start from the app you already use or a number printed on a card you already own.
  • Watch for credit, accounts, phone-number changes and official letters you did not ask for. That is the usual next step when copies of passports and licences have left a company.
  • Assume the email address and phone number in the file will be used to reach you with fake “official” messages about this incident. Do not use links or numbers from those messages.
  • Reduce what people-search and directory sites publish about you. A leaked Revolut record is a bundle of facts sitting on its own. It becomes much more dangerous when those sites bolt on relatives, extra phone numbers, employers and previous addresses. Unlike the stolen copies, those listings can often actually be taken down, which is why that step is worth doing even though it does not reverse the leak.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Revolut.

  1. Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
  2. Report the passport number. A compromised passport number can be reported to the US State Department, which will flag it. Replacing it is neither quick nor free, so report it before you need to travel.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Check your exposure
Revolut is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed September 12, 2026
Last reviewed September 12, 2026
Affected Unconfirmed
Data exposed Full namesDates of birthHome addressesEmail addressesPhone numbersPassport copiesDriver's licencesVerification selfies +2 more
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email