Revolut just admitted its own compliance team handed a criminal customer passports, KYC selfies and complete transaction histories, and nobody hacked the app to get them. The London-based fintech, which serves more than 80 million retail customers and 800,000 businesses across 160-plus countries, disclosed this week that an attacker used a real government agency's own email domain to submit fraudulent requests for customer information. Revolut answered those requests as if they were real, because on paper, they were.
Notifications went out around September 12. Revolut confirmed the details to press by September 14: "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information." In plain terms, someone hijacked a mailbox on a real government domain, then used it to request customer records the way police, tax authorities and regulators do every day. Revolut says it caught the abuse, blocked the address, and alerted the agency, law enforcement, data protection and financial regulators, and that systems and funds were never touched. It won't say which agency, which country, or how many people were affected, only that the figure is "limited."
RelatedBrevo Breach Exposes 347K Trezor Users to Phishing Scam
How did a fake account on a real government domain fool Revolut?
Every bank this size runs a channel for lawful requests from police, courts and regulators: subpoenas, court orders, urgent requests tied to active cases. That channel sits apart from the app, the ledger and customer authentication, none of which were touched here. The attacker didn't breach a server. They needed a mailbox on a domain compliance staff already trust by default, because refusing a genuine government request risks obstructing a real investigation. Once that trust exists, the request looks routine.
It's not a new trick. In 2022, Bloomberg reported that Apple and Meta both handed over data to forged "emergency data requests," a category police can send without a warrant when claiming lives are at risk. Attackers had compromised real law enforcement email accounts and simply asked. The FBI has since warned about this exact pattern. Revolut's breach is the same playbook, aimed at a bank instead of a social network.
Why doesn't email authentication catch a forgery like this?
SPF, DKIM and DMARC answer one question: did this email really come from a server the domain owner authorized. They answer it well. They cannot tell you whether the human behind that server had any right to send this particular request. Get a new mailbox provisioned on the agency's domain, through a compromised admin account, weak internal access controls, or an insider, and every technical check passes cleanly, because the domain genuinely is authorizing the mail. The forgery isn't in the headers. It's in who's typing.
There's no industry-wide standard for closing that gap. A few platforms built their own answer after 2022: verified law-enforcement portals tied to a registered badge number instead of a plain email, plus a callback to a published agency phone line before anything sensitive ships. Banks face legal pressure to answer lawful requests fast, which cuts against pausing for a manual call every time. Revolut plainly didn't require out-of-band verification here, and neither did the compromised agency.
Who was affected, and why does it matter that some are crypto whales?
For the customers hit, the exposure is severe: name, date of birth, occupation, address, email, phone number, passport or driver's licence copies, KYC selfies, account statements, IBAN details, withdrawal records and full transaction histories, including Bitcoin activity. Revolut says facial biometric telemetry wasn't part of the haul.
On-chain investigator ZachXBT flagged the pattern: attackers appear to have targeted wealthy Revolut customers specifically, a small number of high-net-worth accounts rather than a broad scrape. Former Mt. Gox CEO Mark Karpeles confirmed he was among them. Protos reported an alleged demand of 10,000 BTC, roughly $780 million at the time, though that number stays unconfirmed. What isn't in question is the combination: name, address, passport scan and full crypto transaction history in one file is a targeting kit. It feeds SIM-swaps, account-takeover attempts at exchanges leaning on the same KYC documents for recovery, phishing that already knows real transaction amounts, and, for visible crypto wealth, physical risk once address and net worth are both confirmed.
RelatedFrance's Tax Agency Faces Second Breach Claim in Three Days
| Revolut 2026 | Revolut 2022 | Apple/Meta 2022 | |
|---|---|---|---|
| Vector | Forged emergency data request via real .gov domain | Social engineering of staff | Forged emergency data request via compromised police email |
| Data exposed | Passport, selfie, IBAN, full tx history | Names, contact and account data | Names, addresses, phone numbers |
| Customers hit | "Limited number," unconfirmed | 50,150 confirmed | Undisclosed |
| Ransom demand | 10,000 BTC alleged, unconfirmed | None reported | None reported |
- 2022-09Prior Revolut breach Social engineering exposes data on 50,150 customers
- 2022Apple and Meta forged EDR cases Bloomberg reports both firms handed over data to attackers using compromised police emails
- 2026-09-12Revolut notifies customers TechCrunch reports the breach disclosure
- 2026-09-14Revolut statement to press BleepingComputer publishes Revolut's full comment; wider coverage follows
What does this mean for Revolut and the fintechs around it?
Revolut is privately held, so there's no stock chart to watch. The signal for investors: this failure sits in compliance and operations, not the codebase, which is harder to fix with a sprint and harder to catch in due diligence. Any fintech handling government requests at Revolut's scale, across 160-plus jurisdictions with different rules for "urgent," carries the identical gap. Expect regulators in the compromised agency's country to ask how it verifies outgoing requests, and other KYC-heavy platforms to quietly review their own intake procedures this quarter.
Our take
The technology worked exactly as designed, and that's the problem. SPF, DKIM and DMARC confirmed the domain was real. Nothing in that stack was meant to confirm the person behind the keyboard had authority to ask for a stranger's passport, and nobody has built a required substitute. The fix is a process, not a patch: callback verification against a published, static phone number before releasing sensitive data, plus signed request portals with individually registered credentials, the kind Meta and Apple built only after getting burned in 2022. If a bank can freeze a card over one odd purchase, it can hold a document release for the ninety seconds a callback takes.
"Limited number" isn't disclosure, it's a placeholder. Revolut named an exact figure, 50,150, after its 2022 breach. Withholding one now, for passports and KYC selfies rather than contact details, reads like managing headlines over customers. Regulators should press for the count first.
- Which agency gets named. Pressure to disclose the country and agency once investigations allow it.
- A real customer count. Whether Revolut follows its 2022 precedent and publishes a figure instead of "limited."
- Copycat attempts. More banks and exchanges quietly reporting similar attempts now that this one is public.
- Verified request portals. Whether regulators push government agencies toward the signed-portal model Meta and Apple adopted.
If you got the notification, treat it as a full identity exposure, not a minor leak. Request a replacement passport if yours was copied, since the scan is compromised even though the document isn't lost. Switch to hardware two-factor on every exchange or wallet tied to those accounts, not SMS, since your phone number is now exposed. Watch for phishing that quotes your real transaction history back to you. And if your crypto holdings are large enough to be inferable from this breach, treat physical security as part of the response.
- ReportTechCrunch: Revolut confirms data breach 2026-09-12
- ReportBleepingComputer: Revolut discloses breach Revolut's statement, 2026-09-14
- ReportProtos: What we know ZachXBT analysis, alleged ransom
- AdvisoryFBI IC3: fraudulent emergency data requests on compromised government email accounts
- RelatedCVE Watchlist disclosed vulnerabilities
Original analysis by GenZTech. Source: TechCrunch.
