Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 12, 2026, Revolut confirmed a data breach in which an attacker obtained passport copies, verification selfies, and complete transaction histories — including Bitcoin — without ever compromising a corporate system. The vector was a fraudulent email that cleared every authentication check because it originated from an unauthorized account inside a genuine government agency's infrastructure, carrying valid SPF, DKIM, and DMARC. The fintech, which serves more than 80 million customers across over 30 markets, fulfilled the request believing it legitimate, only to discover the deception when it later contacted the agency for validation.
- An unauthorized account in a legitimate government domain sent fraudulent requests that passed as authentic thanks to valid SPF, DKIM, and DMARC.
- Exposed data includes passport or driver's license copies, facial verification selfies, addresses, IBANs, and complete transaction histories with Bitcoin activity details.
- Revolut confirmed that customer funds and core systems were not compromised, nor was the facial biometric telemetry collection exposed.
- The incident appears targeted at high-net-worth customers, according to analyst ZachXBT, though Revolut described the number of affected users as "limited" without providing an exact figure.
How an Authenticated Email Bypassed Compliance Processes
The attack mechanism exemplifies an evolution of institutional phishing that does not rely on domain spoofing but on the use of a real, albeit unauthorized, account within the same government infrastructure. Revolut's spokesperson told TechCrunch that "an unauthorized third party used an email from a legitimate government agency's domain to submit fraudulent information requests." The customer notification, reported by The CyberSec Guru, states that the communication "carried genuine domain authentication credentials," leading Revolut to fulfill the request "with the reasonable belief that it was an authentic request from a government agency."
The distinction is critical: this is not a spoofed domain or typo-squatting, but a message that email authentication infrastructures recognize as legitimate. CryptoSlate confirmed the email passed SPF, DKIM, and DMARC. This scenario invalidates the premise that technical domain validation constitutes sufficient guarantee for sensitive data requests, particularly in fintech where regulatory compliance demands rapid response times to authority requests.
Categories of Data Exposed: From ID Documents to Bitcoin History
The customer notification examined by TechCrunch lists data covering the entire KYC onboarding arc and financial activity. Compromised identity documents include "copies of identity documents including passports and driver's licenses." Facial verification biometric images captured during onboarding were exposed, with a specific exclusion: "no facial biometric telemetry data was involved or compromised," as consistently reported by The CyberSec Guru, Decrypt, and CryptoSlate.
On the financial side, the exposure covers full names, dates of birth, occupations, mailing addresses, emails, and phone numbers. Added to these are IBANs, account status, opening dates, wallet reference numbers, withdrawal records, and, particularly relevant for risk profiling, "complete transaction histories, Bitcoin included." CryptoSlate reported that on-chain analyst ZachXBT indicated the incident was "apparently targeted at high-net-worth users," an element that amplifies physical and social risk consequences.
The KYC Problem as an Attack Surface
The incident reignites the debate over centralization of identification data under Know Your Customer policies. Aave founder Marc Zeller commented on X that the case is a "stark reminder that KYC has not produced significant upside and has put many in danger," as reported by Decrypt. The criticism centers on the paradox whereby mandatory accumulation of highly sensitive documents — driven by anti-money-laundering regulations — creates concentrated targets of exceptional value, without access controls commensurate with the risk.
The procedural question emerges forcefully from the documented gaps in the dossier. It is unknown whether Revolut applied out-of-band verification procedures for government requests, nor why validation occurred only after data delivery. The specific government agency has not been identified. These gaps prevent determining whether the incident represents a compromise of government infrastructure or abusive creation of an internal account, with different implications for systemic risk mitigation.
"An unauthorized third party used an email from a legitimate government agency's domain to submit fraudulent information requests" — Revolut spokesperson to TechCrunch
What to Do Now
The source does not document specific remedial measures taken by Revolut nor recommendations directed at users in the context of this incident. The dossier does not specify whether the exposed information has been observed on criminal markets or whether other financial institutions received similar requests from the same source. Based on verified facts, areas of attention include:
- Monitor unsolicited communications that use exposed data for social-engineering escalation, given that passports, selfies, and financial histories provide material for targeted profiling.
- Evaluate credential-update or account-modification requests that cite details drawn from this breach as a credibility element.
- Consider that the absence of compromised facial biometric telemetry does not exclude re-identification risk through correlation of exposed data.
- Recognize that SPF/DKIM/DMARC validation of a government email no longer constitutes, by itself, proof of the specific sender's authorization.
Why the Fintech Sector Will Watch This Case
Revolut is heading toward a potential listing that sources value at up to $200 billion, up from a previous $75 billion. At this stage, an incident exposing the fragility of legal-request response processes carries regulatory-narrative repercussions as much as technical ones. Supervisory authorities in the 30-plus markets where Revolut operates as a bank will now have to confront whether government-request verification procedures are sufficiently robust relative to the volume and sensitivity of data retained by legal obligation.
The case also signals a possible shift in the threat model: no longer direct compromise of financial institutions, but exploitation of their trust chains toward the state. If threat actors identify that technical domain validation substitutes for procedural sender validation, the vector becomes scalable beyond a single target. Whether other banks received requests from the same source is currently unknown, but the attack structure requires no technical customization to be replicated.
Frequently Asked Questions
- Are Revolut customer funds at risk?
- Revolut explicitly stated that customer funds and core systems were not compromised. The incident concerns exclusively the disclosure of personal and financial data, not access to custody systems.
- Why did the government email pass as authentic?
- Because it originated from an account created within the domain infrastructure of a real agency, resulting in valid SPF, DKIM, and DMARC. Technical domain authentication does not verify the individual sender's authorization.
- What Bitcoin data was exposed?
- The dossier indicates "complete transaction histories, Bitcoin included," which according to sources includes wallet references, withdrawal records, and complete transactional activity. It does not emerge whether private keys or access credentials were exposed.
Sources
- https://cybersecuritynews.com/revolut-data-breach/
- https://thecybersecguru.com/news/revolut-data-breach-2026/
- https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
- https://www.cryptika.com/revolut-data-breach-exposes-customers-passport-copies-and-full-transaction-histories-to-hackers/
- https://decrypt.co/378114/revolut-passports-bitcoin-activity-data-breach
- https://cryptoslate.com/revolut-tricked-into-handing-hackers-the-passports-and-bitcoin-histories-of-wealthy-customers/
- https://cybersecuritynews.com/ai-powered-public-surveillance/
- https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&utm_medium=online_media&utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026
- https://cybersecuritynews.com/
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.