Revolut Reportedly Released Customer Passports and Bitcoin Transaction Logs after Fake Government Email

Revolut customers have been told that a subset of their most sensitive records was released after the company treated a fraudulent information demand as a genuine government inquiry.

The episode became public on 11–12 September 2026 after affected users received notices and investigators circulated excerpts.

It did not depend on a conventional intrusion into Revolut’s networks.

The firm says it handed over data after an unauthorized mailbox sitting inside an official public-authority domain sent a request that carried valid sender-authentication credentials.

According to the customer notice quoted by on-chain investigator ZachXBT and by former Mt. Gox chief Mark Karpelès, who said he received the email himself, the message was framed as a lawful agency request.

Because it originated from an account created within the authority’s own domain infrastructure and passed the checks commonly used to detect spoofed mail—SPF, DKIM and DMARC—Revolut processed it in the belief that it was authentic.

Only later, when the company contacted the agency to confirm the demand, did it learn that the mailbox was unauthorized.

That outreach also alerted the government body to the rogue account on its own systems.

The categories of information listed in the notice go well beyond names and contact details.

Identity fields reportedly included full names, dates of birth and occupations.

Contact data covered home addresses, email addresses and phone numbers.

Document and onboarding files included copies of passports or driving licences plus the verification selfies submitted during know-your-customer checks.

Financial records included IBANs, account statements, withdrawal logs and complete transaction histories, including Bitcoin activity.

Revolut told recipients that biometric facial telemetry was not part of the disclosure.

The incident appears limited in scale.

ZachXBT said it looked targeted at higher-net-worth customers rather than a mass dump of the entire user base.

Revolut has not published an official headcount, named the agency involved, or given dates for when the request arrived and when the data left the firm.

Public reporting likewise has not identified how the unauthorized sender obtained a foothold on the government domain.

Revolut says it has now blocked the address across internal systems, notified relevant regulators and applied extra protective measures for the customers concerned.

Coverage of the notices does not describe any theft of customer balances, and the company has framed the event as an unauthorized disclosure rather than a hack of its core platforms.

The case highlights a weaker point in financial compliance workflows: legal-looking demands that arrive with technically valid mail authentication.

Email standards can confirm that a message left a given domain; they cannot, by themselves, prove that the person who sent it had lawful authority to demand passports, selfies and full crypto ledgers.

For customers, the practical risk is not only identity theft but highly tailored social engineering attacks built from a complete picture of who they are and how they move money.

Affected users should treat unexpected calls or messages that cite this incident with caution, verify any outreach inside the official app, and watch for follow-on phishing.

Broader questions remain for regulators and for every firm that must honour official data requests: how to confirm the human authority behind a technically perfect government email before sensitive KYC files leave the building.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend