Revolut didn't get hacked. It got a letter.
On 12 September, Revolut confirmed that it had handed customer data to an unauthorised third party. Not through a stolen password, an unpatched server or a rogue employee. Through the front door: a request for information that arrived from a real government agency's email domain, passed the technical checks that domain is supposed to guarantee, and was processed by staff doing exactly what the job requires.
A spokesperson called it a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.
The company says its systems and customer funds were unaffected, that a limited number of customers were involved, and that it blocked the address on detection and notified the agency, law enforcement, and its data protection and financial regulators. It has declined to name the agency while investigations continue, and has not published a figure for how many people were affected. Numbers circulating on aggregator sites are not confirmed by anyone who would know.
What was in the envelope
This is the part worth sitting with. Per the notices sent to affected customers and subsequent reporting, the disclosed material included dates of birth, postal and email addresses and phone numbers — and then kept going: copies of identity documents such as passports and driving licences, verification selfies, account statements, and transaction histories.
That is not a password you can rotate. It is the permanent, unrevocable version of you. A leaked card number gets reissued on Tuesday. A passport scan paired with the selfie you took holding it is a working identity kit for as long as the document is valid, and it is the exact bundle needed to open accounts in your name somewhere else.
Reporting indicates the requests were aimed at high-net-worth individuals, a number of them in crypto businesses — which tells you the attacker was not fishing. They were shopping from a list.
Why no security product would have stopped this
Every regulated financial institution runs a process for responding to lawful requests from law enforcement and government agencies. It is not an optional feature or a weakness in the build. It is a condition of holding the licence, and a firm that ignored such requests would be in breach of its obligations within the week.
So the attack surface here is not Revolut's infrastructure. It is the trust relationship between a regulated firm and the state, and the fact that this relationship is authenticated largely by an email domain. Control an account on that domain and you inherit the authority attached to it.
This is a known and recurring failure. In 2021 and 2022, attackers linked to Lapsus$ used compromised law enforcement accounts to send forged emergency data requests to Apple, Meta and Discord, and got user data back. In November 2024 the FBI warned publicly that access to compromised government email accounts was being advertised on criminal forums for precisely this purpose. The technique is a decade old in spirit and it keeps working, because the only real fix is on the government side of the wire.
Now the question this site exists to ask
Revolut is a licensed bank with its own UK and EU authorisations and more than 50 million users. It is among the most scrutinised firms in European fintech. If its disclosure process can be played by a well-formed email, the interesting question is not "is Revolut safe." It is: how many copies of my passport are out there, and who is holding them?
That is answerable from the dataset, so we answered it.
| Identity requirement | Count | What it means |
|---|---|---|
| Full identity verification | 334 | A government ID — typically a passport or licence scan, very often with a selfie — is collected and retained. |
| Card only | 33 | The wallet needs nothing; the card does, because a licensed issuer sits behind it. |
| None | 14 | Self-custodial software. No account, no balance held for you, nothing to verify. |
334 of the 381 neobanks we track hold identity documents for the people who signed up. That is not a criticism of any of them — anti-money-laundering rules across the UK, EU and US require regulated firms to collect those records and to keep them, typically for years after an account is closed. Deleting your account does not delete the file. That is the law working as intended.
It does mean the exposure is cumulative and quiet. Every app you onboarded to and forgot about is still a place where a copy of your passport sits, attached to a disclosure process you have never read, at a company whose name you may struggle to remember.
Two structural details most coverage skips
The partner-bank multiplier. Of those 334, 88 run on the partner-bank model — the app you use is not the licensed entity. The regulatory obligation to know and record who you are sits with the bank underneath, while the onboarding flow that photographed your passport belongs to the app on top. There are at least two organisations in that chain with a compliance reason to hold your file, and only one of them has a logo on your card.
The graveyard problem. We keep an archive of neobanks that have shut down — six so far. When a regulated firm winds up, its AML records do not evaporate; they are retained, transferred to an administrator, or passed to an acquirer, because the retention obligation outlives the product. The company you verified yourself to in 2021 may not exist, but the obligation attached to your documents does.
What is actually worth doing
Not much of the usual advice applies, so here is the short, honest list.
- Reduce the count. The only variable genuinely under your control is how many firms hold your documents. Close the accounts you do not use — it will not delete the records already held, but it stops the number growing.
- Know which structure you are in. Whether a licensed bank or a partner arrangement holds your money and your file changes who is accountable when something goes wrong. Every profile here states it; this post explains how to read it.
- Treat ID-document reuse as the real risk. If you are notified that your documents were disclosed, the follow-on threat is account opening and takeover elsewhere in your name, not fraud on the account that leaked. Credit freezes and monitoring are aimed at the right target; changing your banking password is not.
- Ask for the retention answer. UK and EU customers can make a subject access request and ask what identity material is held and for how long. Few people do. The answers are instructive.
Revolut will absorb this. It has the balance sheet, the regulatory relationships and the legal position — it was deceived by something carrying the marks of state authority, which is a defensible place to be. The awkward part is what it reveals about the shape of the system rather than the conduct of one firm: the perimeter everybody spends money defending is not where this data leaves. It leaves through a process that is legally obliged to exist, authenticated by a domain name, at 334 companies at once.