Revolut Data Breach: Passports, Selfies and Bitcoin Records Sent to a Fake Government Request

Revolut has confirmed that it disclosed sensitive customer information — including passport and driver's licence copies, verification selfies and complete Bitcoin transaction histories — to an unauthorised third party after being fooled by fraudulent requests sent from inside a legitimate government agency's email domain.

Sep 12, 2026 - 17:22
0 4
Revolut Data Breach: Passports, Selfies and Bitcoin Records Sent to a Fake Government Request

Revolut has confirmed that it disclosed sensitive customer information — including passport and driver's licence copies, verification selfies and complete Bitcoin transaction histories — to an unauthorised third party after being fooled by fraudulent requests sent from inside a legitimate government agency's email domain. The London-based fintech said the request cleared its email authentication controls because it carried genuine domain credentials, and that it fulfilled it "under the reasonable belief that it was an authentic government agency request," according to a notification emailed to affected customers and reported by TechCrunch on 12 September 2026. A Revolut spokesperson said a "limited" number of customers were impacted and that the company had contacted those customers directly, while declining to disclose how many were affected, which market was involved, or which agency was impersonated. The customer notice began circulating on 11 September, weeks after Revolut received conditional approval from the US Office of the Comptroller of the Currency to establish a national bank in the United States.


REVOLUT CONFIRMS IT DISCLOSED CUSTOMER PASSPORTS, VERIFICATION SELFIES AND BITCOIN HISTORIES AFTER A FRAUDULENT REQUEST SENT FROM A GOVERNMENT EMAIL DOMAIN

London, United Kingdom — Revolut confirmed on 12 September 2026 that it handed identity documents, contact records and complete crypto transaction histories to an unauthorised third party after receiving fraudulent information requests that arrived from a genuine government agency's email domain, according to a notification the firm emailed to affected customers.

What Revolut Confirms

In a statement to TechCrunch, a Revolut spokesperson described the episode as "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information." The company confirmed that a "limited" number of customers were impacted, that it contacted those customers directly, and that it blocked the email address after discovering the scam. Revolut said it alerted the relevant government agency, law enforcement and relevant regulators, and added that "Revolut systems and customer funds are unaffected."

The customer notice, quoted by crypto.news, states: "As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request." The same notice does not say that an intruder entered Revolut's systems, accessed customer accounts or withdrew funds. ETHNews reported that the attacker never touched Revolut's servers, and that rather than probing firewalls or databases the sender issued an information request from an official government agency's email domain signed with valid authentication credentials. London-based Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries, according to TechCrunch.

The Email That Passed Every Automated Check

CryptoSlate reported that the attacker used an unauthorised mailbox inside a genuine government domain, allowing the request to clear Revolut's authentication controls. The fraudulent email passed SPF, DKIM and DMARC authentication — the mechanisms designed to verify that messages are authorised by the domain they claim to represent — which, per CryptoSlate, suggests the attacker had access to an unauthorised mailbox within the government agency's actual email infrastructure rather than simply changing the sender information on a conventional spoofed email.

ETHNews described the failure as procedural rather than technical. Every automated control that a data request is supposed to clear, the publication reported, this email cleared; the one check that would have stopped it — verifying the sender's authority instead of the sender's domain — was the check nobody ran. Because the message carried genuine domain headers, Revolut's automated anti-spoofing filters read it as authentic. The Crypto Times, quoting the notice, reported that the request "originated from an unauthorized email account created directly within an official government authority's domain infrastructure" and "carried genuine domain authentication credentials."

What Left the Building

The data category list is broad. According to the notification and the reporting around it, the disclosure included full names, dates of birth and occupations; postal addresses, email addresses and telephone numbers; and a copy of the identity document such as a passport or driver's licence, plus the facial verification image submitted at onboarding.

Account records were also included. Statements carried IBANs, account status, account-opening dates and Bitcoin wallet reference numbers, while withdrawal records and full transaction histories — including Bitcoin transactions — were provided, according to crypto.news and CryptoSlate. TechCrunch reported that the exposed information included customers' identity and contact details, covering birth date, postal and email addresses and phone numbers, plus copies of identity documents including passports and driver's licences, and that it may also have included verification selfies, account statements and transaction histories.

A smartphone displaying the Revolut logo

What Was Not Disclosed

CryptoSlate reported that no funds, passwords, PINs or private keys were reportedly compromised. Revolut told BeInCrypto that passcodes, login details and biometric data were not exposed and that no customer funds moved, according to Sovereign Magazine.

Revolut drew a distinction on biometrics: the notice states that no biometric facial telemetry data was involved, even though it lists the verification selfie itself among the documents disclosed. CoinCentral reported that Revolut clarified that private keys, account passwords and full payment card details were not part of the disclosure.

The omissions are equally specific. Revolut did not disclose the exact number of impacted individuals, did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved, TechCrunch reported. The notice does not name the agency, does not say how the unauthorised sender obtained access to its email domain, and gives no date for the request or the disclosure, according to crypto.news. No coins have been reported moved on 11 or 12 September.

Who Found Out and How

The crypto security researcher ZachXBT posted about Revolut's email to affected customers late on Friday 11 September, according to TechCrunch, and said the incident appeared to have been targeted at high net worth users. The Crypto Times reported that the customer notice began circulating on 11 September.

Mark Karpeles, the former Mt. Gox chief executive, posted substantial excerpts of the notice at 07:06 UTC on 12 September, identifying himself as a recipient. Per The Crypto Times, Karpeles said he received the email with the subject line "Urgent security update about your Revolut account" at 21:59 UTC on 11 September, after posting a public inquiry directed at the company at 21:05 UTC the same day asking whether the reported data leak was authentic. ZachXBT posted screenshots at 06:51 UTC on 12 September indicating he had been blocked by both @Revolut and @revolutsupport; a follow-up post at 07:18 UTC said he had visited the accounts to check whether Revolut had posted about the incident and then found the blocks, adding: "Idk why I am blocked by both Revolut accounts." Revolut Support replied to a user at 06:42 UTC on 12 September saying "We take data protection and privacy concerns very seriously," without adding facts beyond the customer email.

The Agency Revolut Will Not Name

Revolut has not identified the impersonated agency, citing the police investigation, Sovereign Magazine reported. It has not given a date for the fraudulent request, only that customers were emailed on Friday 11 September.

Karpeles argued that identifying the compromised government agency could allow other banks and exchanges to determine whether they also received information demands from the same mailbox. As of 09:13 UTC on 12 September 2026, according to The Crypto Times, several elements remained unconfirmed: the exact number of customers, the country or name of the impersonated agency, the date the files left the firm, whether other financial institutions received the same mailbox, whether the third party has since reused the information, and whether a public statement from Revolut's main account will follow.

Why Bitcoin Histories Change the Threat

The Crypto Times reported that pairing a full transaction history and wallet reference number with a passport image, verification selfie, IBAN and residential address produces a richer package than a typical email-and-password leak. It can support targeted phishing, account-recovery social engineering, and chain analysis that begins from a legal name rather than from an unnamed cluster.

ETHNews characterised the incident as a hand-picked set of wealthy profiles rather than a bulk data dump, shifting the primary risk away from routine identity theft toward spear-phishing, coercion, and in the worst case physical extortion against people confirmed to hold significant crypto. Security researchers have warned for years, ETHNews noted, that publicly linking wealth to a residential address invites so-called wrench attacks, where a holder is threatened in person to surrender funds that remain otherwise cryptographically secure. The publication also observed that the 2022 wave of fake "emergency data requests" that struck Meta, Apple, Discord and Snap ran on the same logic: a trusted institutional sender, a request dressed as urgent and official, and a human on the receiving end who complied. Crypto protocols are down at least $1.3 billion to hacks through August 2026, though most of those drained funds directly rather than harvesting identities.

The comparison cases are narrower. In September 2022, Lithuania's State Data Protection Inspectorate recorded that 50,150 Revolut customers were affected after a social engineering attack against staff. On 9 September 2026, Trezor said a compromised Brevo newsletter account was used to send a fake "Critical Security Alert: STM32 Entropy Vulnerability" to approximately 347,000 subscribers — a case that affected only opt-in newsletter addresses and did not involve KYC files. The UK Information Commissioner's Office says possible consequences of a personal data breach include identity theft, fraud and financial loss, and its guidance calls for an assessment of the information involved and the likely harm to individuals; it does not establish that anyone has suffered those outcomes in the Revolut incident. Regulator guidance also says organisations must report certain personal data breaches within 72 hours of becoming aware of them, where feasible, and notify individuals without undue delay when the risk to their rights and freedoms is high.

An illustration depicting a fraudulent data request, identity documents and a locked account

A Fintech Weeks Away From a US Bank Charter

On 3 September 2026 Revolut received conditional approval for a US bank charter from the Office of the Comptroller of the Currency, according to CoinCentral. TechCrunch reported that Revolut expects to launch the national bank in the first half of 2027. The firm has also secured banking licences in France and the UK in recent months and recently expanded in India, Mexico, France and the UAE.

On the corporate side, Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November, per TechCrunch and Mezha. On 26 August 2026, crypto.news reported, Revolut began offering its euro-backed EURR stablecoin to selected customers in Denmark, Poland and Portugal, with further European availability planned. Revolut has not publicly commented on the incident beyond the customer notice, and has not identified the agency whose email domain was used, CoinCentral reported.

The Unanswered Question of Out-of-Band Verification

Revolut has not explained why it released records before confirming the request outside email, and CryptoSlate listed the outstanding questions: whether government information requests require confirmation outside email, why Revolut contacted the agency only after releasing customer records, and whether it has changed that process. ETHNews reported that Revolut caught the fraud only after contacting the impersonated agency through a separate channel, by which point the records had already left the building.

What Revolut says it has done since is documented. It blocked the address across internal systems, notified relevant regulators, alerted the government agency and law enforcement, placed affected accounts under precautionary monitoring and began contacting affected individuals directly, describing the episode to crypto outlets including BeInCrypto as a sophisticated external impersonation attack. In US security guidance, Revolut told customers to use in-app support chat to check whether a suspicious contact is genuine, and says it will not ask customers to share verification or security codes over the phone. ETHNews framed the residual exposure bluntly: a leaked password costs an afternoon; a leaked passport tied to a wallet history is a standing exposure that no reset resolves.

By Jessica Ali, Staff Writer

This article was produced with AI-assisted research and editorial support. Sources: TechCrunch, CryptoSlate, crypto.news, The Crypto Times, ETHNews, Sovereign Magazine, CoinCentral, Mezha.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Jessica Ali

Editor-in-Chief at Global1.News. Atlanta-based journalist who cuts through the BS and tells it like it is. Lead anchor, host, and the voice you hear when the spin stops and the truth starts.

Comments (0)

User