Revolut Covered Document Costs After Data Breach
The fintech firm offered to pay for identity replacements after a targeted email-based security compromise.
Updated on Oct. 7, 2026 in Cybersecurity

Live Poll
Do you trust digital banking platforms to keep your identity documents secure from hackers?
On September 12, 2026, Revolut announced that it is covering the replacement costs for identification documents belonging to 680 affected clients. This breach occurred after an unauthorized party used a government email domain to access sensitive customer records.
Why it matters
The incident highlights the ongoing risk of credential-based social engineering attacks against financial institutions. By using a legitimate government domain to bypass filters, the attackers successfully accessed high-value data like verification selfies and transaction histories.
The unauthorized party exploited a government agency email domain to submit fraudulent information requests. This method bypassed standard verification, exposing birth dates, email and postal addresses, phone numbers, passports, and driver's licenses.
The players
Revolut
A global fintech company providing digital banking services, including currency exchange and stock trading.
The details
The breach was executed when an unauthorized actor utilized a legitimate government email domain to submit fraudulent requests that bypassed traditional authentication layers. Once the scheme was detected, Revolut blocked the compromised email address, but not before the attacker had exfiltrated identity documents including passports, driver's licenses, and account statements. The company reported the incident to law enforcement and data-protection authorities after an extortion attempt followed the initial access.
Timeline
September 12, 2026: Revolut notified customers and media of the data breach.
September 16, 2026: Reports emerged regarding extortion threats from a hacker.
The Tech Race
Financial institutions continue to harden their verification stacks against spoofed government domains, which remain a primary vector for circumventing automated security. This incident underscores the ongoing arms race between fintech security protocols and attackers using legitimate digital infrastructure.
Customers identified as part of the 680-person cohort are eligible for Revolut-funded document replacement. Those impacted should monitor their personal accounts for suspicious activity, as birth dates, addresses, and transaction histories were compromised in the incident.
The takeaway
This event illustrates that even strictly regulated financial interfaces are vulnerable to external domain-spoofing attacks. Affected users should maintain heightened vigilance regarding identity theft and monitor official communications for further remediation guidance.
Further reading
For broader trends in financial platform security, see the Cybersecurity section.
Live Poll
Do you trust digital banking platforms to keep your identity documents secure from hackers?






