Revolut handed customers' passports, selfies and bitcoin histories to a fake government request

12.09.2026 7 min 26

Revolut has told a group of customers that it handed their identity documents, verification selfies, account statements and full transaction histories, bitcoin included, to someone who asked for them in the name of a government agency. Nobody broke in. The request arrived from a mailbox on the agency's real domain, passed the checks that confirm a sender's domain, and was fulfilled "under the reasonable belief that it was an authentic government agency request". The alert emails went out on 11 September 2026.

In brief

  • A single fraudulent request, not a hack: Revolut's own notice says the sender used an unauthorised account on an official government domain with valid domain authentication.
  • What left the company: names, dates of birth, occupations, addresses, phones, emails, passport or licence copies, the verification selfie, IBANs, statements, withdrawal records and full transaction history including bitcoin.
  • On-chain investigator ZachXBT, who published the notice, says the group is likely small and looks aimed at wealthy users. Revolut, which in May handed 304 subscribers' data to Sky Ireland under a court order, has not said how many people, which agency or when.
  • Handing data over on an official-looking request is a pattern: this spring Google gave an activist's bank records to ICE without telling him. Here the requester was not even real, and a KYC file is the richest target such a request can hit.

What Revolut told the affected customers

The notice, published as a screenshot by ZachXBT on 12 September, is short and unusually specific about what went out. Revolut "received a request for customer information that appeared to come from a legitimate government agency". The request "came from an unauthorised email account sent directly using the official government agency's email domain". Because it "carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request". The company says it has notified the relevant regulators and applied precautionary protection measures; its support account added only that it takes data protection "very seriously".

The list of disclosed data is the part to read twice. Identity details: full name, date of birth, occupation. Contact details: postal address, email, telephone. Document and verification data: a copy of the passport or driving licence and the facial verification image, the selfie taken at sign-up, with the caveat that "no biometric facial telemetry data" was involved. Financial data: account statements including IBAN, account status, opening date and wallet reference number, withdrawal records and full transaction history including bitcoin. The notice lists categories that may have been disclosed, not a per-customer inventory, and it does not mention passwords, card numbers or private keys.

11.09.2026the day the alert emails reached customers, according to ZachXBT
4categories of data in the notice: identity, contact, documents and selfie, finances
80 M+Revolut customers worldwide; the affected group is described as small and targeted
0details on the agency, the country, the date of the request or the number of people affected

How a fake request passes the checks

The phrase "valid domain authentication credentials" explains the failure better than Revolut probably intended. Email authentication, the SPF, DKIM and DMARC records that mail servers check, proves that a message really came from the domain it claims. It proves nothing about who was sitting at the keyboard. If the sender used an account on the agency's actual domain, every technical check passes, because technically the email is genuine. The only defence left is procedural: calling the agency back on a known number, demanding a court order or a signed form, refusing to treat an email as sufficient for a passport and a full ledger.

This is not a new trick. In 2022 it emerged that Apple and Meta had given user data to criminals who sent forged emergency requests from hacked law-enforcement email accounts. Those requests worked because they looked urgent and arrived from the right domain, the same two properties visible here. What has changed is the payload. A social network holds an IP address and a phone number. A regulated fintech holds the complete know-your-customer file, which is exactly the set of documents that lets someone open accounts, pass checks and convince a carrier to move a phone number.

Worth separating: nothing in the notice suggests Revolut's systems were breached, accounts accessed or money moved. The failure is in the process that decides when a government request is real. That is a smaller hole than a hack and, for the people whose files went out, a worse one, because a passport copy and a transaction history cannot be reset like a password.

What this file allows

Put the categories together and the recipient has what a targeted attack needs. Name, date of birth, address and document copy are enough for identity theft and for passing many providers' verification. Phone number plus identity documents is the starting kit for a SIM swap, and a SIM swap is how two-factor codes sent by SMS end up with someone else. The transaction history, with bitcoin withdrawals to specific wallets, tells the recipient who holds crypto, how much has moved and where, which is why ZachXBT's remark about high-net-worth users matters: the same data that enables online fraud also enables someone to show up at an address. Revolut was not the only company handing over bank and crypto data this month; it is the first to do so for a request that turned out to be fake.

If you received the email

  1. Verify through the app only. Revolut's own guidance says to use in-app support chat to check whether a contact is genuine; expect calls and messages from people who now know your name, bank and balance and will pretend to be Revolut, the police or a tax office.
  2. Lock your phone number. Ask your carrier for a port-out or SIM-change PIN and move two-factor codes off SMS wherever the service allows an authenticator app or a hardware key.
  3. Assume the document copy is permanently out. Ask your issuing authority whether a passport or licence can be reissued with a new number; where it cannot, a fraud alert or credit freeze with the credit bureaus in your country is the fallback.
  4. Treat every exchange and wallet linked to the disclosed history as a known target. Change passwords, review withdrawal whitelists and login alerts, and consider whether funds sitting at an address now tied to your name should stay there.
  5. Ask Revolut, in writing, for the full record: what was sent, when, to whom, and which regulator was notified. Under UK and EU data protection law you are entitled to that, and the answer determines what else you need to do.
Was Revolut hacked?
Not according to its notice. It describes a request that appeared to come from a government agency and was fulfilled. The data left through the front door.
Which agency and which country?
Revolut has not said. The notice mentions only "the official government agency's email domain". It also gives no date for the request or the disclosure.
How many customers are affected?
Unknown. ZachXBT, who saw multiple alerts, calls the incident likely limited in size and apparently aimed at wealthy users. Revolut has published no figure.
Were passwords, cards or private keys exposed?
The notice does not list them. It lists identity and contact details, document copies with the selfie, and financial records including bitcoin transaction history.
Does the "no biometric telemetry" line mean the selfie is harmless?
No. It means the mathematical face template was not shared. The photograph itself, paired with a passport copy, is what other services ask for at sign-up.

revolutdata breachkycbitcoincryptocurrencyidentity theftsim swapidentity verificationpersonal dataprivacyukzachxbt

Read also