Privacy & Data 6 min read

Nobody Broke Into Revolut. Someone Asked, From a Government Domain.

Passports, verification selfies and full transaction histories went out through the channel that answers official requests — the one channel a customer cannot see, decline or authenticate.

Priya Nair
Data, AI Governance & Policy Analyst
Published 14 Sep 2026, 7:07 AM (SGT)
Share:
A hand holding out a passport against a plain wall — illustrating the identity documents Revolut disclosed to a fraudulent request. A hand holding out a passport against a plain wall — illustrating the identity documents Revolut disclosed to a fraudulent request. Photo by sarahpassos on Pixabay
Advertisement

14 SEP 2026 — Revolut has told customers that their passports, verification selfies and full transaction histories were handed to an unauthorised third party. Nothing was hacked. Somebody sent an email from a legitimate government agency domain asking for the records, and the request was answered.

Revolut is firm that its systems held. "Revolut systems and customer funds are unaffected," it says, and on the evidence available that is true. No compromised app, no account takeover, no money moved. The failure was in the human process that answers official letters.

Revolut's account of it

According to the disclosure reported on 12 September, an unauthorised party used an email account on a genuine government agency domain to submit fraudulent requests for customer information. Revolut describes it as a sophisticated external impersonation scam. The address was blocked once identified, and the company says it notified the relevant agency, law enforcement, data protection authorities and financial regulators.

The notification sent to affected customers lists what went out: names, dates of birth, postal and email addresses, phone numbers, copies of identity documents such as passports and driving licences, identity-verification selfies, account statements, IBANs, withdrawal records and complete transaction histories including Bitcoin activity.

Revolut has not said how many people were affected beyond calling the number limited, has not named the market or markets involved, and has not identified the agency whose domain was used. The onchain investigator ZachXBT, who surfaced the notifications, suggested the targets were high-net-worth users, which is his reading rather than the company's.

The channel nobody audits

Every regulated financial institution runs a queue for official requests. Police forces, tax authorities, courts and financial-intelligence units all have lawful routes to customer records, and a bank that ignored them would be in breach of its licence. The queue has to exist and it has to be answered.

It is also, by design, the one channel where the customer has no say. A user cannot decline it, cannot see it, and is not usually told it happened. There is no second factor on a subpoena.

Abusing that queue is not a new idea. The technique of forging law-enforcement data requests to extract subscriber records from platforms has been documented since at least 2022, when several large technology companies confirmed they had been deceived by the same approach. What has changed is the value of the target. A social platform holds an address and an IP log; a fully regulated bank holds the identity dossier it was legally obliged to collect.

0Systems compromised, by Revolut's account
1Email domain, belonging to a real agency
LimitedThe only figure given for affected customers
UnnamedThe agency whose domain was used

Worse than a leaked password

A leaked password is an inconvenience with a fix. You change it, and the leaked value is worthless within seconds.

A passport scan paired with a verification selfie cannot be revoked. It is what a know-your-customer check demands, so it is also what opens an account somewhere else in the victim's name. The selfie matters more than people assume: liveness checks have pushed fraudsters towards stolen video and images, and a verification photo taken under a bank's own instructions is close to ideal input.

A transaction history is merely embarrassing for an ordinary customer. For someone holding meaningful crypto balances it is a targeting document, because it shows the size of the holdings, the exchanges, the withdrawal patterns and the addresses. Wrench attacks against identified holders happen, and this is the intelligence that picks the victim.

What the customer could have done

Nothing. The reflexive advice after a breach is to tighten your own account, and here it does not apply.

Advertisement

A hardware key would not have helped. Neither would a strong password, a fresh device, a passkey, or any other control that stops account takeover. None of them touch a disclosure made through the front door by the compliance team. That team was not authenticating the customer; it was authenticating a government.

The only meaningful protections here are institutional. A bank can require that official requests arrive over an authenticated channel rather than by email, call the requesting agency back on a number it looks up independently, and treat a bulk request for identity documents as an escalation rather than a ticket. Whether Revolut did any of these, and where the check broke, is exactly what the disclosure does not say.

The disclosure has holes

Revolut has been quicker and clearer than many institutions are in the same position. Customers were told directly, the technique was described rather than hidden behind the word incident, and regulators were engaged.

The gaps still matter. No count means nobody outside the company can judge the scale, and no named market means the public cannot see which regulator owns the question. Withholding the agency is the costliest of the three: it is the one piece of information that would let other institutions check whether the same domain has been pointed at them.

Revolut serves more than 80 million customers across more than 30 countries and holds conditional approval for a United States banking licence. An impersonation route into a business of that size is an industry problem, not one company's embarrassment.

The questions still open

A regulator's findings would be the most useful outcome. Data protection authorities in the affected market have the notification, and their conclusions would establish what verification a bank owes before it answers a government email.

Then watch for other institutions disclosing. One usable agency domain was probably pointed at more than one firm, and in 2022 a single technique surfaced across several companies over several weeks.

The lasting fix is not a better email filter. It is a request channel where the requesting authority proves itself cryptographically. Nothing like that exists in most jurisdictions, and building one would take years.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement