Security · Analysis
Revolut Gave Passports and Bitcoin Histories to a Fake Official
The request came from an email account on a real government agency's domain, and Revolut filled it. The company won't say how many customers were affected, which agency it was, or which country. Two days later, a group claiming to hold the files started asking for money.
Nobody broke into Revolut. According to the company, someone sent it an email asking for customer records, and Revolut sent the records back. The email came from an account on a government agency's real domain. That's the whole mechanism Revolut has described so far, and it's enough to explain how passport scans, verification selfies and full transaction histories, including bitcoin activity, ended up with a stranger.
Affected customers started getting notification emails on Friday, September 11, The Block reported. The on-chain investigator ZachXBT publicized the notice the same day, and former Mt. Gox CEO Mark Karpelès posted a copy of the one he received. On Saturday, Revolut confirmed the incident to TechCrunch. A spokesperson said the company "recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."
What went out
According to the notice as TechCrunch and The Block describe it, the exposed data covered dates of birth, postal and email addresses, phone numbers, and copies of passports or driving licences. It may also have included the selfies customers took for identity checks, account statements and transaction histories. Help Net Security reports that ZachXBT's post listed items the company's own account left out: IBANs, withdrawal records, occupations, and transaction history covering bitcoin. CoinDesk and Decrypt list the same bitcoin histories.
Revolut says it blocked the address once it spotted the scheme, told the government agency involved, and alerted law enforcement, data-protection authorities and financial regulators. CoinDesk quotes its statement: "Revolut systems and customer funds are unaffected." The company said it had contacted "the limited number of impacted individuals directly."
That's close to the full public record. Revolut declined to tell TechCrunch how many customers were affected, whether the incident was confined to one market, or which agency's domain was used. It hasn't said when the request arrived, how long it took to notice, or whether the email claimed an emergency or attached a legal order. ZachXBT's read, as TechCrunch and CoinDesk relay it, is that the incident looked limited in scale and aimed at wealthy customers. That's an informed guess, not a figure.
A real domain proves less than it looks
The detail doing the most work in Revolut's account is "legitimate government agency domain." Email authentication can tell a recipient that a message really came from the domain it claims. It can't tell the recipient whether the person typing had the authority to ask. If the account was compromised or misused, every technical check passes. Revolut hasn't said which of those it was, and this desk isn't assuming either.
The method isn't new. In March 2022, KrebsOnSecurity reported that criminals were using hacked police email accounts to send fake "emergency data requests." That's the channel police use to get subscriber data without a court order when a life is said to be at risk. Krebs documented that Discord had fulfilled one. In the same piece, former federal prosecutor Mark Rasch said providers publish contact points for emergency requests but have "no real mechanism" to test whether a warrant or subpoena is valid.
In November 2024, the FBI warned US companies directly. The bureau said criminals were "likely gaining access to compromised US and foreign government email addresses" and using them for fraudulent data requests, SecurityWeek reported. The notice cited a March 2024 forum claim of government email access in 25 countries and an August 2024 listing that sold .gov addresses for this exact use. It told recipients to check documents for doctored signatures and logos and to confirm that cited legal codes match the authority making the request.
From forged police requests to a fintech's KYC files
| When | What happened |
|---|---|
| Mar 2022 | Krebs reports fake emergency data requests sent from hacked police email accounts |
| Mar 2024 | A forum actor claims government email access in 25 countries, usable for fake subpoenas (per FBI) |
| Aug 2024 | .gov email addresses advertised for data requests (per FBI) |
| Nov 2024 | FBI warns US companies about fraudulent requests from compromised government accounts |
| Fri, Sep 11, 2026 | Revolut customers receive breach notices; ZachXBT publicizes one |
| Sat, Sep 12 | Revolut confirms to TechCrunch; declines to give numbers, market or agency |
| Sun, Sep 13 | International Cyber Digest posts about leak threats (per Finbold, CoinCentral) |
| Mon, Sep 14 | A 10,000 BTC demand figure is reported, attributed to Coin Bureau (per Finbold); unverified |
The extortion claim, and what's still unverified
By Sunday, the story had moved from a disclosure to a shakedown, at least by some accounts. Help Net Security cites a Reddit post claiming a group is leaking data "purportedly belonging to VIP clients," demanding payment, and threatening to release private messages, client files and internal material. CoinCentral says the threat came over Telegram and quotes it: "We're going to start releasing more and more data everyday until revolut pays." Finbold puts the demand at 10,000 BTC. It attributes that figure to Coin Bureau on X, and says International Cyber Digest first posted about the threats on Sunday.
The outlets don't agree on where the demand appeared, and CoinCentral doesn't give an amount. This desk hasn't seen the demand itself and can't confirm that the group holds data from this incident, rather than simply claiming it. Several outlets name individuals whose documents the group says it released. We aren't repeating names that come from a leak. Revolut hasn't publicly addressed the demand.
Why a bank leak is a crypto story
A passport scan and a home address are serious on their own. Pair them with a selfie and a transaction history that shows bitcoin buys and withdrawals, and the file tells a stranger who someone is, what they look like, where they sleep, and roughly what they hold. Decrypt reported that ZachXBT's framing, that the data seemed aimed at wealthy users, raised concerns about "wrench attacks," the industry term for physical coercion of known crypto holders.
In the past three weeks this desk has covered SafePal's order records for 39,798 hardware-wallet buyers, a business-intelligence flaw at a fulfilment contractor that exposed hardware-wallet owners' home addresses, and a newsletter provider that BitBox believes was breached, after Trezor and BitBox customers got the same fake alert. In none of them was a wallet, key or contract at fault. Revolut's case has no vendor in the middle, by its own account. The request went to Revolut, and Revolut answered it.
The Take
Revolut's statement leans on the same sentence every one of these disclosures leans on: systems and funds are unaffected. It's true, and it misses the point. The asset that left was the KYC file, the one thing regulators require a platform to collect and guard. The fix isn't a better spam filter, because a compromised government account passes every filter. It's a callback: before sending identity documents to anyone claiming authority, a person verifies the request through a phone number or portal the company already has on file for that agency, not one taken from the email. The FBI told companies to scrutinize exactly these requests nearly two years ago. Revolut owes its customers three numbers it has so far withheld: how many people, which country, and how long the files were out before anyone noticed.