BLOCKCHAIN AI.NEWS

Security · Analysis

Revolut Gave Passports and Bitcoin Histories to a Fake Official

The request came from an email account on a real government agency's domain, and Revolut filled it. The company won't say how many customers were affected, which agency it was, or which country. Two days later, a group claiming to hold the files started asking for money.

Editorial illustration: a frosted glass envelope with a blank chrome seal pushing through a narrow slot in a steel wall, beside an open chrome drawer glowing gold with glass cards lifting out of it
✓ Customer notice publicized by ZachXBT (Sep 11) · Confirmed by Revolut to TechCrunch (Sep 12) · Also reported by The Block, CoinDesk, Decrypt and Help Net Security · Extortion claims via Finbold and CoinCentral · Background: FBI notice via SecurityWeek, KrebsOnSecurity · Italian investigation via Cointelegraph and Euronews · Updated Sep 20, 2026
Update, Sep 20, 2026: Italy has opened a criminal investigation into the channel used to make the request. Cointelegraph reported on September 16 that the Polizia Postale, Italy's cybercrime police, is investigating for unauthorised access to a computer system and computer fraud, and that the requests were sent through Posta Elettronica Certificata (PEC) — Italy's certified email system, which gives a message the legal standing of registered mail. Italian media identified the compromised account as belonging to the Prefecture of Reggio Calabria; ANSA reported that the agency denied sending any requests to Revolut. Revolut declined to name the agency, citing the active investigation, and said its systems, databases and customer funds remained secure. Prosecutors in Reggio Calabria have opened a case, and the National Anti-Mafia and Anti-Terrorism Directorate is involved because a government communication channel is implicated. Italy's CERT-AGID, which warned in June that PEC certifies delivery but not the security of a message's contents, has handled more than 650 cases involving compromised or illicit PEC accounts since the start of 2026. Separately, Euronews reported on September 17 that an actor calling itself "iamnotavillain" demanded roughly 6,000 XMR — about $3 million — within 24 hours, and that Revolut confirmed data belonging to around 680 European customers was affected while their funds were untouched.

Nobody broke into Revolut. According to the company, someone sent it an email asking for customer records, and Revolut sent the records back. The email came from an account on a government agency's real domain. That's the whole mechanism Revolut has described so far, and it's enough to explain how passport scans, verification selfies and full transaction histories, including bitcoin activity, ended up with a stranger.

Affected customers started getting notification emails on Friday, September 11, The Block reported. The on-chain investigator ZachXBT publicized the notice the same day, and former Mt. Gox CEO Mark Karpelès posted a copy of the one he received. On Saturday, Revolut confirmed the incident to TechCrunch. A spokesperson said the company "recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."

What went out

According to the notice as TechCrunch and The Block describe it, the exposed data covered dates of birth, postal and email addresses, phone numbers, and copies of passports or driving licences. It may also have included the selfies customers took for identity checks, account statements and transaction histories. Help Net Security reports that ZachXBT's post listed items the company's own account left out: IBANs, withdrawal records, occupations, and transaction history covering bitcoin. CoinDesk and Decrypt list the same bitcoin histories.

Revolut says it blocked the address once it spotted the scheme, told the government agency involved, and alerted law enforcement, data-protection authorities and financial regulators. CoinDesk quotes its statement: "Revolut systems and customer funds are unaffected." The company said it had contacted "the limited number of impacted individuals directly."

That's close to the full public record. Revolut declined to tell TechCrunch how many customers were affected, whether the incident was confined to one market, or which agency's domain was used. It hasn't said when the request arrived, how long it took to notice, or whether the email claimed an emergency or attached a legal order. ZachXBT's read, as TechCrunch and CoinDesk relay it, is that the incident looked limited in scale and aimed at wealthy customers. That's an informed guess, not a figure.

A real domain proves less than it looks

The detail doing the most work in Revolut's account is "legitimate government agency domain." Email authentication can tell a recipient that a message really came from the domain it claims. It can't tell the recipient whether the person typing had the authority to ask. If the account was compromised or misused, every technical check passes. Revolut hasn't said which of those it was, and this desk isn't assuming either.

The method isn't new. In March 2022, KrebsOnSecurity reported that criminals were using hacked police email accounts to send fake "emergency data requests." That's the channel police use to get subscriber data without a court order when a life is said to be at risk. Krebs documented that Discord had fulfilled one. In the same piece, former federal prosecutor Mark Rasch said providers publish contact points for emergency requests but have "no real mechanism" to test whether a warrant or subpoena is valid.

In November 2024, the FBI warned US companies directly. The bureau said criminals were "likely gaining access to compromised US and foreign government email addresses" and using them for fraudulent data requests, SecurityWeek reported. The notice cited a March 2024 forum claim of government email access in 25 countries and an August 2024 listing that sold .gov addresses for this exact use. It told recipients to check documents for doctored signatures and logos and to confirm that cited legal codes match the authority making the request.

From forged police requests to a fintech's KYC files

WhenWhat happened
Mar 2022Krebs reports fake emergency data requests sent from hacked police email accounts
Mar 2024A forum actor claims government email access in 25 countries, usable for fake subpoenas (per FBI)
Aug 2024.gov email addresses advertised for data requests (per FBI)
Nov 2024FBI warns US companies about fraudulent requests from compromised government accounts
Fri, Sep 11, 2026Revolut customers receive breach notices; ZachXBT publicizes one
Sat, Sep 12Revolut confirms to TechCrunch; declines to give numbers, market or agency
Sun, Sep 13International Cyber Digest posts about leak threats (per Finbold, CoinCentral)
Mon, Sep 14A 10,000 BTC demand figure is reported, attributed to Coin Bureau (per Finbold); unverified
Compiled by this desk from KrebsOnSecurity, SecurityWeek (on the FBI notice), The Block, TechCrunch, Finbold and CoinCentral. Revolut hasn't said whether its request was framed as an emergency; the earlier rows show the pattern, not the Revolut method.

The extortion claim, and what's still unverified

By Sunday, the story had moved from a disclosure to a shakedown, at least by some accounts. Help Net Security cites a Reddit post claiming a group is leaking data "purportedly belonging to VIP clients," demanding payment, and threatening to release private messages, client files and internal material. CoinCentral says the threat came over Telegram and quotes it: "We're going to start releasing more and more data everyday until revolut pays." Finbold puts the demand at 10,000 BTC. It attributes that figure to Coin Bureau on X, and says International Cyber Digest first posted about the threats on Sunday.

The outlets don't agree on where the demand appeared, and CoinCentral doesn't give an amount. This desk hasn't seen the demand itself and can't confirm that the group holds data from this incident, rather than simply claiming it. Several outlets name individuals whose documents the group says it released. We aren't repeating names that come from a leak. Revolut hasn't publicly addressed the demand.

Why a bank leak is a crypto story

A passport scan and a home address are serious on their own. Pair them with a selfie and a transaction history that shows bitcoin buys and withdrawals, and the file tells a stranger who someone is, what they look like, where they sleep, and roughly what they hold. Decrypt reported that ZachXBT's framing, that the data seemed aimed at wealthy users, raised concerns about "wrench attacks," the industry term for physical coercion of known crypto holders.

In the past three weeks this desk has covered SafePal's order records for 39,798 hardware-wallet buyers, a business-intelligence flaw at a fulfilment contractor that exposed hardware-wallet owners' home addresses, and a newsletter provider that BitBox believes was breached, after Trezor and BitBox customers got the same fake alert. In none of them was a wallet, key or contract at fault. Revolut's case has no vendor in the middle, by its own account. The request went to Revolut, and Revolut answered it.

The Take

Revolut's statement leans on the same sentence every one of these disclosures leans on: systems and funds are unaffected. It's true, and it misses the point. The asset that left was the KYC file, the one thing regulators require a platform to collect and guard. The fix isn't a better spam filter, because a compromised government account passes every filter. It's a callback: before sending identity documents to anyone claiming authority, a person verifies the request through a phone number or portal the company already has on file for that agency, not one taken from the email. The FBI told companies to scrutinize exactly these requests nearly two years ago. Revolut owes its customers three numbers it has so far withheld: how many people, which country, and how long the files were out before anyone noticed.

More on the subject