Revolut handed customers' passports, selfies and bitcoin histories to a fake government request
Revolut has told a group of customers that it handed their identity documents, verification selfies, account statements and full transaction histories, bitcoin included, to someone who asked for them in the name of a government agency. Nobody broke in. The request arrived from a mailbox on the agency's real domain, passed the checks that confirm a sender's domain, and was fulfilled "under the reasonable belief that it was an authentic government agency request". The alert emails went out on 11 September 2026.
In brief
- A single fraudulent request, not a hack: Revolut's own notice says the sender used an unauthorised account on an official government domain with valid domain authentication.
- What left the company: names, dates of birth, occupations, addresses, phones, emails, passport or licence copies, the verification selfie, IBANs, statements, withdrawal records and full transaction history including bitcoin.
- On-chain investigator ZachXBT, who published the notice, says the group is likely small and looks aimed at wealthy users. Revolut, which in May handed 304 subscribers' data to Sky Ireland under a court order, has not said how many people, which agency or when.
- Handing data over on an official-looking request is a pattern: this spring Google gave an activist's bank records to ICE without telling him. Here the requester was not even real, and a KYC file is the richest target such a request can hit.
What Revolut told the affected customers
The notice, published as a screenshot by ZachXBT on 12 September, is short and unusually specific about what went out. Revolut "received a request for customer information that appeared to come from a legitimate government agency". The request "came from an unauthorised email account sent directly using the official government agency's email domain". Because it "carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request". The company says it has notified the relevant regulators and applied precautionary protection measures; its support account added only that it takes data protection "very seriously".
The list of disclosed data is the part to read twice. Identity details: full name, date of birth, occupation. Contact details: postal address, email, telephone. Document and verification data: a copy of the passport or driving licence and the facial verification image, the selfie taken at sign-up, with the caveat that "no biometric facial telemetry data" was involved. Financial data: account statements including IBAN, account status, opening date and wallet reference number, withdrawal records and full transaction history including bitcoin. The notice lists categories that may have been disclosed, not a per-customer inventory, and it does not mention passwords, card numbers or private keys.
How a fake request passes the checks
The phrase "valid domain authentication credentials" explains the failure better than Revolut probably intended. Email authentication, the SPF, DKIM and DMARC records that mail servers check, proves that a message really came from the domain it claims. It proves nothing about who was sitting at the keyboard. If the sender used an account on the agency's actual domain, every technical check passes, because technically the email is genuine. The only defence left is procedural: calling the agency back on a known number, demanding a court order or a signed form, refusing to treat an email as sufficient for a passport and a full ledger.
This is not a new trick. In 2022 it emerged that Apple and Meta had given user data to criminals who sent forged emergency requests from hacked law-enforcement email accounts. Those requests worked because they looked urgent and arrived from the right domain, the same two properties visible here. What has changed is the payload. A social network holds an IP address and a phone number. A regulated fintech holds the complete know-your-customer file, which is exactly the set of documents that lets someone open accounts, pass checks and convince a carrier to move a phone number.
What this file allows
Put the categories together and the recipient has what a targeted attack needs. Name, date of birth, address and document copy are enough for identity theft and for passing many providers' verification. Phone number plus identity documents is the starting kit for a SIM swap, and a SIM swap is how two-factor codes sent by SMS end up with someone else. The transaction history, with bitcoin withdrawals to specific wallets, tells the recipient who holds crypto, how much has moved and where, which is why ZachXBT's remark about high-net-worth users matters: the same data that enables online fraud also enables someone to show up at an address. Revolut was not the only company handing over bank and crypto data this month; it is the first to do so for a request that turned out to be fake.
If you received the email
- Verify through the app only. Revolut's own guidance says to use in-app support chat to check whether a contact is genuine; expect calls and messages from people who now know your name, bank and balance and will pretend to be Revolut, the police or a tax office.
- Lock your phone number. Ask your carrier for a port-out or SIM-change PIN and move two-factor codes off SMS wherever the service allows an authenticator app or a hardware key.
- Assume the document copy is permanently out. Ask your issuing authority whether a passport or licence can be reissued with a new number; where it cannot, a fraud alert or credit freeze with the credit bureaus in your country is the fallback.
- Treat every exchange and wallet linked to the disclosed history as a known target. Change passwords, review withdrawal whitelists and login alerts, and consider whether funds sitting at an address now tied to your name should stay there.
- Ask Revolut, in writing, for the full record: what was sent, when, to whom, and which regulator was notified. Under UK and EU data protection law you are entitled to that, and the answer determines what else you need to do.
Was Revolut hacked?
Which agency and which country?
How many customers are affected?
Were passwords, cards or private keys exposed?
Does the "no biometric telemetry" line mean the selfie is harmless?
• Community alert: Revolut appears to have exposed PII for a subset of users - ZachXBT, Telegram, 12 September 2026 (with the customer notice)
• Revolut exposed Bitcoin records after fake agency request - crypto.news
• Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email - The Crypto Times