Revolut Says It Will Pay: What Happens When Your Bank Gives Your Personal Data to a Fake Authority?

8th October 2026

For anyone who has ever worried about their bank details, passport or driving licence falling into the wrong hands, the latest Revolut data breach makes uncomfortable reading.

The issue is not simply that criminals hacked into a bank and stole information. According to reports, an attacker managed to impersonate an Italian government agency and persuaded Revolut to provide personal information belonging to customers.

Now Revolut says it will pay the cost of replacing identity documents for affected customers if that becomes necessary.

That sounds reassuring. But it also raises a much bigger question.

What happens when a bank or financial company is tricked into handing over your personal information to the wrong people?

What actually happened?

The incident involved around 680 Revolut customers, according to Reuters.

The attacker apparently gained access to an unused email address associated with an Italian government agency. That email address was then used to make a request for customer information which Revolut treated as legitimate.

The information obtained included personal data and identity documents. European cybersecurity officials said the exposed material also included account statements containing IBANs and transaction histories, including Bitcoin transactions.

The important distinction is that this was not a conventional attack in which criminals broke through Revolut's own computer systems and took a database.

Instead, the attacker appears to have used a trusted identity to persuade Revolut to provide the information.

That makes the incident particularly interesting.

The weakest link may not be where you expect[/b]

Banks spend enormous sums protecting their computer systems.

Firewalls, encryption, passwords, two-factor authentication and fraud monitoring are all designed to stop criminals getting into accounts.

But there is another vulnerability.

People can be fooled.

If a request appears to come from a government department, police force, solicitor or another trusted organisation, staff may be more inclined to believe that the request is genuine.

That appears to be the issue now being questioned in the Revolut case.

Italy's interior minister, Matteo Piantedosi, criticised Revolut's handling of the request and suggested that basic checks could have prevented the information from being released. Revolut, for its part, has said its internal systems were not compromised and pointed to weaknesses involving the government agency's systems.

That disagreement matters because it gets to the heart of the problem.

If a criminal manages to impersonate an authority, who is responsible when the bank accepts the impersonation?

Revolut says it will pay for new identity documents

Revolut's Western Europe chief executive Béatrice Cossa-Dumurgier has said the company will cover the cost of new identity documents for affected customers if they need to replace them.

That is a significant commitment.

Having personal identification stolen is not simply an inconvenience. A passport, driving licence or other official document can be used as part of attempts to impersonate someone.

Even if no money is immediately stolen, victims can be left wondering whether somebody might try to open an account, obtain credit, carry out fraud or impersonate them months later.

Revolut says it has been assisting the 680 affected customers.

It also says no ransom was demanded or paid.

But replacing an identity document is only part of the problem

This is where the story becomes more complicated.

Suppose somebody gets hold of your passport details, address, bank statements and transaction history.

Replacing your passport might cost money.

But what about the time spent dealing with the problem?

What about checking credit reports?

What if somebody subsequently tries to take out credit in your name?

What if you start receiving convincing scam emails because criminals now know which bank you use, roughly how much money moves through your account, or who you make payments to?

And what happens if the stolen information is combined with information obtained somewhere else?

The value of personal information is that it can be combined.

One piece of information may seem harmless. Several pieces together can provide a remarkably detailed picture of a person.

This is not the same as losing money through a scam

There is another important distinction.

Revolut already has rules for reimbursing certain customers who lose money through Authorised Push Payment fraud, where a criminal tricks someone into sending money to an account controlled by the fraudster.

Under its current UK rules, eligible claims can be reimbursed up to £120,000, subject to conditions and a £100 excess.

But that is a different situation.

In an APP scam, the customer has actually lost money.

In the data breach, the immediate problem is that personal information has been exposed.

The danger may come later.

That makes compensation much harder to define.

How do you put a price on the possibility that your identity information could be misused six months or two years from now?

Revolut is now a UK bank

There is another reason the story is worth watching in Britain.

Revolut became a fully authorised UK bank in March 2026, regulated by the Financial Conduct Authority and Prudential Regulation Authority. Eligible deposits with Revolut Bank UK Ltd are protected by the Financial Services Compensation Scheme, subject to the normal rules and limits.

But FSCS protection is primarily about protecting eligible deposits if a bank fails.

It does not mean that customers automatically receive £120,000 if their personal information is stolen.

The two issues should not be confused.

Could this happen to a traditional bank?

Absolutely.

Revolut is getting attention because it is a large and rapidly growing financial technology company, but the underlying problem is much wider.

Traditional banks, building societies, insurers, credit-card companies, government departments, retailers and other organisations all hold huge quantities of personal information.

And the more organisations that hold our information, the more opportunities there are for criminals to exploit weaknesses.

Sometimes the weakness will be technical.

Sometimes it will be a stolen password.

Sometimes it will be an employee being deceived.

And sometimes it may be another organisation in the chain that is compromised.

The customer, however, is usually the same person at the end of it.

What should customers do?

The sensible response is not to panic.

People should be particularly suspicious of unexpected calls, texts or emails following a data breach.

A criminal who knows that you bank with Revolut, for example, may later send a message claiming to be from Revolut and referring to the incident.

That could make the scam look much more convincing.

The safest approach is to contact the bank through its official app or a trusted telephone number rather than using contact details supplied in an unexpected message.

And never assume that because somebody knows your name, address, account details or other personal information, they must be genuine.

In fact, the more information a caller already knows about you, the more cautious you should be.

The bigger question for banks

The Revolut case highlights a problem that is likely to become increasingly important.

Banks are expected to protect customers not only from hackers breaking into their systems but also from criminals manipulating the people and organisations around them.

That means the question cannot simply be:

"Was the bank's computer system hacked?"

It also needs to be:

"Did the bank take reasonable steps to make sure the person asking for our information was actually entitled to receive it?"

That is a much harder question.

And it could become increasingly important as artificial intelligence makes convincing emails, documents and impersonations easier to produce.

Personal data is becoming almost as valuable as money

Most people think about a bank protecting their money.

Increasingly, they also need to think about a bank protecting their identity.

Money can be replaced.

A compromised identity can be much harder to put right.

Revolut's decision to pay for replacement identity documents is therefore welcome. But it may only be the beginning of the debate.

If a financial institution gives your information to somebody who should never have received it, should the customer have to carry the risk of what happens next?

That is the real question raised by the Revolut affair.

And it is a question that will not disappear with this particular data breach.

In a world where our financial lives are increasingly digital, protecting the customer means protecting the information about the customer too.