risk & regulation

Revolut didn't get hacked. It got a letter.

September 15, 2026 · 7 min read · ← all posts · the dataset

On 12 September, Revolut confirmed that it had handed customer data to an unauthorised third party. Not through a stolen password, an unpatched server or a rogue employee. Through the front door: a request for information that arrived from a real government agency's email domain, passed the technical checks that domain is supposed to guarantee, and was processed by staff doing exactly what the job requires.

A spokesperson called it a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information. The company says its systems and customer funds were unaffected, that a limited number of customers were involved, and that it blocked the address on detection and notified the agency, law enforcement, and its data protection and financial regulators. It has declined to name the agency while investigations continue, and has not published a figure for how many people were affected. Numbers circulating on aggregator sites are not confirmed by anyone who would know.

What was in the envelope

This is the part worth sitting with. Per the notices sent to affected customers and subsequent reporting, the disclosed material included dates of birth, postal and email addresses and phone numbers — and then kept going: copies of identity documents such as passports and driving licences, verification selfies, account statements, and transaction histories.

That is not a password you can rotate. It is the permanent, unrevocable version of you. A leaked card number gets reissued on Tuesday. A passport scan paired with the selfie you took holding it is a working identity kit for as long as the document is valid, and it is the exact bundle needed to open accounts in your name somewhere else.

Reporting indicates the requests were aimed at high-net-worth individuals, a number of them in crypto businesses — which tells you the attacker was not fishing. They were shopping from a list.

Why no security product would have stopped this

Every regulated financial institution runs a process for responding to lawful requests from law enforcement and government agencies. It is not an optional feature or a weakness in the build. It is a condition of holding the licence, and a firm that ignored such requests would be in breach of its obligations within the week.

So the attack surface here is not Revolut's infrastructure. It is the trust relationship between a regulated firm and the state, and the fact that this relationship is authenticated largely by an email domain. Control an account on that domain and you inherit the authority attached to it.

This is a known and recurring failure. In 2021 and 2022, attackers linked to Lapsus$ used compromised law enforcement accounts to send forged emergency data requests to Apple, Meta and Discord, and got user data back. In November 2024 the FBI warned publicly that access to compromised government email accounts was being advertised on criminal forums for precisely this purpose. The technique is a decade old in spirit and it keeps working, because the only real fix is on the government side of the wire.

the uncomfortable partThere is no setting in your banking app labelled "do not comply with valid-looking legal process." Two-factor authentication, a strong password, a passkey, a hardware key — none of them are in the path of this attack. You were never the one being authenticated.

Now the question this site exists to ask

Revolut is a licensed bank with its own UK and EU authorisations and more than 50 million users. It is among the most scrutinised firms in European fintech. If its disclosure process can be played by a well-formed email, the interesting question is not "is Revolut safe." It is: how many copies of my passport are out there, and who is holding them?

That is answerable from the dataset, so we answered it.

Identity requirementCountWhat it means
Full identity verification334A government ID — typically a passport or licence scan, very often with a selfie — is collected and retained.
Card only33The wallet needs nothing; the card does, because a licensed issuer sits behind it.
None14Self-custodial software. No account, no balance held for you, nothing to verify.

334 of the 381 neobanks we track hold identity documents for the people who signed up. That is not a criticism of any of them — anti-money-laundering rules across the UK, EU and US require regulated firms to collect those records and to keep them, typically for years after an account is closed. Deleting your account does not delete the file. That is the law working as intended.

It does mean the exposure is cumulative and quiet. Every app you onboarded to and forgot about is still a place where a copy of your passport sits, attached to a disclosure process you have never read, at a company whose name you may struggle to remember.

Two structural details most coverage skips

The partner-bank multiplier. Of those 334, 88 run on the partner-bank model — the app you use is not the licensed entity. The regulatory obligation to know and record who you are sits with the bank underneath, while the onboarding flow that photographed your passport belongs to the app on top. There are at least two organisations in that chain with a compliance reason to hold your file, and only one of them has a logo on your card.

The graveyard problem. We keep an archive of neobanks that have shut down — six so far. When a regulated firm winds up, its AML records do not evaporate; they are retained, transferred to an administrator, or passed to an acquirer, because the retention obligation outlives the product. The company you verified yourself to in 2021 may not exist, but the obligation attached to your documents does.

What is actually worth doing

Not much of the usual advice applies, so here is the short, honest list.

Revolut will absorb this. It has the balance sheet, the regulatory relationships and the legal position — it was deceived by something carrying the marks of state authority, which is a defensible place to be. The awkward part is what it reveals about the shape of the system rather than the conduct of one firm: the perimeter everybody spends money defending is not where this data leaves. It leaves through a process that is legally obliged to exist, authenticated by a domain name, at 334 companies at once.

go deeperAll 334 neobanks that hold identity documents — the full list, each linked to its profile · Revolut's profile — licences, custody, every field with its source · Who actually holds your money — how to read the structures above.