BREAKING: Revolut Handed Customer Passports and Bitcoin History to Hackers Posing as Government

Revolut, the UK-based digital banking and fintech platform with over 70 million customers globally, has confirmed that it disclosed highly sensitive customer data including passport copies, verification selfies, account statements, and full Bitcoin transaction histories to an unauthorised third party after being deceived by fraudulent requests sent via a legitimate government agency’s email domain.
The incident, which surfaced publicly on September 12, 2026 after being flagged by blockchain investigator ZachXBT, represents one of the most significant social engineering attacks against a major financial institution in recent memory and a warning to every regulated business that handles government information requests.
What Happened
Revolut received what appeared to be lawful information-demand emails from a government agency. The emails passed every technical authentication check and were sent from a genuine government domain, carried valid SPF, DKIM, and DMARC authentication credentials, and bore all the hallmarks of a legitimate legal information request.
Financial institutions like Revolut are legally required to comply with official data requests from law enforcement and government agencies. Revolut’s team, operating under the reasonable belief that the request was authentic, fulfilled it.
They were not.
The emails were sent from an unauthorised mailbox that had been established within the genuine government agency’s email domain — a compromised or fraudulently created account that allowed the attacker to send emails that were technically indistinguishable from legitimate government correspondence.
Revolut confirmed: “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
Upon detection, Revolut said it “immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”
What Data Was Exposed
The breadth of data disclosed is alarming. Revolut confirmed the following categories of customer information were handed to the attacker:
Identity and contact information:
Full name, date of birth, occupation, postal address, email address, phone number.
Identity documents:
Passport copies, driver’s licence copies, verification selfies — facial images submitted during KYC onboarding.
Financial records:
Account statements with IBAN numbers, account status and opening dates, wallet reference numbers, withdrawal records, and complete transaction history including Bitcoin transactions.
Revolut stated that biometric facial telemetry data was not part of the disclosure. However the verification selfies — photographs submitted by customers to confirm their identity during onboarding — were included.
Why This Attack Is Particularly Dangerous
This incident differs fundamentally from a conventional data breach. No malware was used, no credentials were leaked, no endpoint was compromised. The attacker forged the authority of a government agency and Revolut’s process for validating that authority failed.
This is a textbook example of a Legal Process Attack — a social engineering technique that exploits the compliance obligations of regulated institutions rather than their technical vulnerabilities. The attacker did not need to penetrate Revolut’s systems. They simply needed to appear to be someone Revolut was legally required to obey.
The combination of data exposed is uniquely damaging for several reasons:
Identity documents plus financial records cannot be reset. Unlike a stolen password or compromised credit card number, a passport copy paired with a full transaction history is permanently sensitive information. There is no way to change your passport history or your date of birth.
Bitcoin transaction histories de-anonymise cryptocurrency holders. Financial intermediaries can connect identity information to on-chain activity, turning a customer database into a map linking a real person to their on-chain activity — which malicious actors may use to target large Bitcoin holders. In the cryptocurrency community, this creates significant physical security risk — individuals known to hold substantial cryptocurrency are targets for robbery and extortion.
KYC data is the most valuable identity fraud package available. The combination of a verified photograph, government-issued ID, date of birth, address, and financial history is everything an identity fraudster needs to open financial accounts, take out loans, or commit tax fraud in a victim’s name.
Who Was Targeted
ZachXBT, the blockchain investigator who first drew attention to the incident, said the breach appeared limited in size and may have targeted high-net-worth customers. This targeting pattern is consistent with the nature of the data sought — Bitcoin transaction histories are most valuable to attackers when they reveal significant cryptocurrency holdings.
Revolut has not disclosed the number of affected customers. Affected individuals began receiving notification emails on Friday, September 12, 2026.
Revolut’s History With Data Incidents
This is not Revolut’s first data exposure. In September 2022, a breach exposed 50,150 customers’ names, addresses, email addresses, phone numbers, partial card data, and past transactions, beginning with a phished employee credential and a highly targeted social engineering campaign.
The recurrence raises questions about the robustness of Revolut’s processes for validating information requests — particularly for a company that has recently received conditional approval from the US Office of the Comptroller of the Currency to establish a national bank in the United States.
The Broader Lesson: When Phishing Targets Processes Not People
Most phishing awareness training focuses on teaching individuals to recognise suspicious emails. This attack bypasses that training entirely.
The Revolut incident is an example of what security researchers call Business Process Compromise — attacks that target organisational workflows and compliance obligations rather than individual users’ credentials. The attack succeeded not because a Revolut employee clicked a phishing link, but because Revolut’s legal compliance process for responding to government data requests had an insufficient verification step.
This is why government-impersonation phishing has become a priority threat against regulated industries. The pretext exploits the one behaviour security awareness training struggles to eliminate: deference to authority under time pressure. It targets the process rather than the password. Multi-factor authentication is irrelevant when the credential was never stolen — the attacker never needed a session cookie because the data arrived as an attachment.
What Regulated Organisations Must Do Now
If your organisation receives and processes legal information requests from government agencies, law enforcement, or regulators, this incident demands an immediate review of your verification procedures.
Verification must go beyond email authentication. The fact that an email passes SPF, DKIM, and DMARC checks confirms only that it was sent from the claimed domain — not that the sender was authorised to send it. A compromised or fraudulently created mailbox within a government domain will pass all technical authentication checks.
Implement out-of-band verification for sensitive data requests. Before disclosing any customer data in response to a government request, call the relevant agency directly using a telephone number sourced independently — not from the email itself. Confirm that the request is genuine and that the specific email address is authorised.
Establish a legal process review workflow. Any request for customer data should pass through a defined review chain that includes legal counsel or a data protection officer before disclosure, regardless of how urgent the request appears. Urgency is a social engineering lever, not a legitimate reason to bypass verification.
Train specifically on legal process attacks. Brief your legal, compliance, and data protection teams on the risk of fraudulent government impersonation requests. This is a distinct attack type that requires specific awareness beyond standard phishing training.
Document every disclosure. Maintain a complete record of every information request received, the verification steps taken, and the data disclosed. This is essential for regulatory compliance and for rapid response if a request later proves fraudulent.
What Affected Revolut Customers Should Do
If you have received a notification from Revolut confirming your data was included in this disclosure, take the following steps:
Treat your identity documents as permanently compromised. While you cannot replace your date of birth or your transaction history, you can take steps to limit the damage. Inform your bank of the incident and request additional authentication measures on your accounts.
Be alert to follow-on phishing. The attacker now has your name, email address, phone number, and postal address. Expect highly personalised phishing attempts across all channels — email, SMS, and phone — in the coming weeks. Be especially suspicious of any contact purporting to be from Revolut, your bank, HMRC, or law enforcement.
Monitor your credit file. Register with a credit monitoring service and check for any new credit applications made in your name. In the UK, Experian, Equifax, and TransUnion all offer free basic monitoring.
Secure your cryptocurrency. If your Bitcoin transaction history was exposed, consider moving holdings to hardware wallets not associated with your exposed identity. Do not discuss your holdings publicly.
Report suspicious contact. If you receive suspicious follow-up contact exploiting information from this breach, report it to Action Fraud (actionfraud.police.uk), the ICO (ico.org.uk), and PhishScout (phishscout.net).
Revolut’s Statement
Revolut has confirmed the incident and stated that customer funds and systems are unaffected. The company says it has blocked the fraudulent email address, alerted the relevant government agency to the unauthorised mailbox operating within their domain, and notified data protection and financial regulators.
The company has not named the government agency involved, explained how the attacker established an unauthorised mailbox within the agency’s domain, or disclosed the number of customers affected.
PhishScout will update this advisory as further information becomes available.
Conclusion
The Revolut incident is a landmark case in the evolution of social engineering attacks against regulated financial institutions. It demonstrates that even technically sophisticated organisations with robust cybersecurity infrastructure can be compromised through the manipulation of legal compliance processes.
The attack required no malware, no zero-day exploit, and no technical breach. It required only the patience to establish access to a government email domain and the knowledge that financial institutions are legally obligated to respond to government information requests without sufficient independent verification.
Every regulated institution — fintech, bank, healthcare provider, law firm — that processes government information requests should treat this incident as a direct warning and review their verification procedures today.
PhishScout is tracking this incident. Submit related phishing attempts at phishscout.net
Sources: TechCrunch, CoinDesk, BNO News, The CyberSec Guru — September 12, 2026