Revolut Sent Passports and Bitcoin Histories After a Fake Government Request
• September 12, 2026 2:39 pm • CommentsRevolut sent a package of sensitive customer information to an unauthorized third party after treating a fraudulent government request as legitimate.
The exposed material went far beyond an email address or account number. Affected customers were told it could include identity documents, verification selfies, home addresses, account statements, wallet reference numbers and complete transaction histories—including Bitcoin activity.
CryptoSlate reports that the request came from an unauthorized mailbox created inside a real government agency’s domain infrastructure. The message carried valid domain-authentication credentials, which made it look substantially more convincing than an ordinary spoofed email.
Revolut fulfilled the request under the belief that it came from the agency. The company later contacted that agency to verify the request, learned that the mailbox was unauthorized, blocked the address in its systems, notified regulators and began contacting affected customers.
The customer notice listed names, dates of birth, occupations, postal addresses, email addresses and phone numbers among the possible disclosures. It also listed passport or driver’s-license copies, the facial image used during account verification, IBAN details, account status and opening dates.
On the crypto side, the notice included withdrawal records, wallet reference numbers and full transaction histories that could contain Bitcoin activity. Revolut said biometric facial telemetry was not involved, drawing a line between the stored verification image and the derived biometric data used to analyze a face.
Revolut customers were targeted in a fraudulent emergency data request sent via an email at a "government agency." https://t.co/sS2sbwAt8r
— Mark Karpelès (@MagicalTux) September 12, 2026
The incident is not being described as a breach of Revolut’s production systems, and no stolen customer funds had been reported when the story emerged. Private keys, passwords and card PINs were not among the data categories listed in the customer notice.
That does not make the exposure harmless. Combining a passport image, verification selfie, address, IBAN and Bitcoin history gives an attacker a detailed map for targeted phishing and account-recovery fraud.
It can also connect a legal identity to crypto activity that a customer may have assumed was difficult for strangers to trace. Even without a private key, that intelligence could help criminals craft believable messages, impersonate support staff or choose high-value targets.
The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or “we will close your account in 20 days”
Now we know they been fooled by hackers and did all the work for them like good little lap dogs.
— Marc Zeller (@mzeller) September 12, 2026
CoinDesk also reported that the unauthorized request appeared to come from a genuine government email address. That detail is the central security failure: normal SPF, DKIM and DMARC checks can show that a message came through an authorized server for a domain, but they cannot prove that the human controlling a mailbox is authorized to make a particular legal demand.
The breach therefore exposes a weakness in the process around sensitive requests, not in Bitcoin’s network. A financial company can use strong email authentication and still need a separate, out-of-band method to confirm the agency, investigator, case number and legal authority before releasing customer records.
Revolut has not publicly identified the government agency involved or disclosed the exact number of affected customers. The company described the group as limited, according to reports, but the risk for each person depends on the specific records included in the response.
Affected customers should treat unexpected calls, emails and account-recovery messages as especially suspicious. Anyone contacting them may know details that ordinarily make a scam sound legitimate.
The practical lesson for crypto users is uncomfortable but straightforward. Centralized services collect identity information to satisfy compliance obligations, and those records can become more revealing when paired with wallet and transaction data.
This was not a failure of Bitcoin’s cryptography. It was a failure to verify who was asking for the records before the records left the building.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
