This is starting to feel like a pattern. Weeks ago it was IDScan.net, a vendor that verifies IDs at bars and rental counters. It leaked 153 million driver's license scans. Now it's Revolut, an online bank with more than 80 million customers. Passports, driver's licenses, and verification selfies ended up with cybercriminals. Different company, same lesson. Your identity documents are only as safe as the weakest company holding a copy of them.
In September 2026, Revolut confirmed that an outside attacker tricked the company into handing over customer data. The attacker impersonated a real government agency's email domain. The bank treated the requests as genuine and released the files. Revolut says its systems and customer funds were not touched. The documents were.
This wasn't a hack. It was a con.
Most breaches you read about involve a server getting broken into. This one didn't. The attacker used a legitimate government agency's email domain. It looked like an official data request. It passed the standard checks companies use to confirm an email is real. Revolut's staff had no clean way to tell it apart from a genuine legal order. So they complied.
That's the uncomfortable part. No password got guessed. No firewall got breached. A company simply trusted the wrong email. Real identity documents walked out the door because of it.
Reporting on the leaked files describes passports, driver's licenses, and verification selfies. Also included: full transaction histories, IBANs, names, dates of birth, addresses, phone numbers, and occupations. Revolut has not said how many customers were affected, calling it a "limited number." The company says affected people were told directly.
The extortion angle
Whoever holds this data isn't staying quiet about it. The attacker began publishing identity documents and selfies publicly. They reportedly demanded 10,000 Bitcoin, worth roughly $782 million. The threat: leak more files every day until paid. Whether or not that ransom gets paid, the documents already public do not become private again.
Why this matters even if you don't use Revolut
A leaked passport or driver's license photo is not like a leaked password. You can't reset it. A stolen SSN mostly enables financial fraud. A real photo ID paired with a real selfie does something different. That exact combination is what many other companies use to verify a new customer is who they say they are. It's valuable because it can be reused to pass identity checks somewhere else entirely.
If you bank with Revolut, or with any company that holds a scan of your ID, the same defense applies.
- Freeze your credit. Free at Equifax, Experian, and TransUnion. It blocks the most common thing a stolen identity document gets used for: opening new accounts in your name.
- Be suspicious of contact that references your real details. Someone quoting your actual address or account number back to you is not proof they're legitimate. It just means your data is out there.
- Watch for account-opening confirmations you didn't request. A real photo ID can pass identity checks at other companies. Got a confirmation email for something you never signed up for? That's a real warning sign, not spam to ignore.
- If you were notified by Revolut directly, take that seriously. A direct notification means your specific documents are confirmed exposed, not just possibly.
Was your email tied to this breach or any other?
Our free scan shows which known breaches contain your email and whether identity data was exposed alongside it.
Run the Free Breach Scan →