VERSE PRESS

Crypto News, Global First.

Revolut Handed Passports and Bitcoin Histories to Fraudsters Posing as a Government Agency

Revolut confirmed on September 12, 2026, that it released sensitive customer data to an unauthorized third party after receiving a fraudulent data request sent from a compromised legitimate government email domain.

|

Revolut confirmed on September 12, 2026, that it released sensitive customer data to an unauthorized third party after receiving a fraudulent data request sent from a compromised legitimate government email domain. The exposed records include passport and driver's license copies; KYC verification selfies; full names, dates of birth, and occupations; home addresses, email addresses, and phone numbers; IBANs; account statements; withdrawal records; and complete Bitcoin transaction histories.

Customer funds, passwords, card PINs, private keys, and biometric facial telemetry data were not accessed.

The fintech giant, which serves more than 70 million customers globally and offers crypto services across 31 countries, said a "limited" number of customers were affected. It has not disclosed the exact figure or identified which government agency's domain was hijacked. The company says it notified affected users directly, blocked the fraudulent sender, and alerted law enforcement and regulators.

How the Attack Worked

The fraudulent request passed all standard email authentication checks, including SPF, DKIM, and DMARC verification. Those protocols confirm that an email originates from a legitimate domain, but they cannot detect whether the person sending from that domain is authorized to do so. Revolut only discovered the deception after independently reaching out to the relevant agency, by which point the data had already been released. A company spokesperson described the incident as "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."

This attack method is a variation of what cybersecurity researchers call Emergency Data Request (EDR) fraud. In genuine EDRs, law enforcement agencies send expedited requests for user data to platforms in urgent situations. Because the process runs on email, a compromised government mailbox is all an attacker needs to make the request appear completely authentic. EDR fraud was first publicly documented by security researcher Brian Krebs in 2022, when attackers were found impersonating law enforcement across major tech platforms.

Threat intelligence firm Brinztech issued a global alert in June 2026 documenting underground criminal forums actively auctioning access to verified government and law enforcement email accounts, with prices ranging from $5 to $400 per account, marketed specifically for use against technology companies.

Who Is at Risk and Why the Bitcoin Data Matters

Onchain investigator ZachXBT flagged the incident publicly, stating: "While the incident is likely limited in size it seems to have been targeted at high net worth users."

The combination of records exposed makes this breach particularly serious: a complete dossier containing a person's legal name, home address, passport photograph, verification selfie, and full Bitcoin transaction history gives criminal actors everything they need to identify and locate a crypto holder.

That threat is not hypothetical. Physical robberies and kidnappings targeting crypto holders, commonly called wrench attacks, are on pace for a record year. Blockchain analytics firm Chainalysis reports $30 million stolen in the first half of 2026 alone. The rate of such incidents jumped 75 percent year-over-year, according to CoinDesk reporting from February 2026. France has become the global epicenter, recording 41 crypto-linked kidnappings in 2026 as of publication, roughly one every 2.5 days. Criminal groups building targeting profiles routinely use leaked exchange KYC data to connect real-world identities to wallet addresses and wealth estimates. The 2020 Ledger hardware wallet breach is widely cited as the incident that normalized this threat model.

Marc Zeller of the Aave Chan Initiative voiced a frustration shared by many affected users: "The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or 'we will close your account in 20 days.'" Former Mt. Gox CEO Mark Karpelès noted a practical consequence Revolut has not addressed: "Identifying the compromised agency would help other financial institutions determine if they received requests from the same mailbox."

Regional Context

Revolut's South Africa launch is not expected before 2028, and the platform remains inaccessible in Nigeria, so customers in both countries face no immediate account-level risk. That said, the attack vector demonstrated here is not Revolut-specific. Fintech KYC pipelines operated by companies like Flutterwave and Chipper Cash in Nigeria and Kenya rely on similar compliance workflows and are not inherently protected against EDR fraud. African users who hold Revolut accounts through diaspora networks, particularly Nigerian communities in the UK using the platform for cross-border Bitcoin settlements, are potentially among those affected.

In South Asia, Revolut's Indian beta program is limited in scope, but Indian-heritage users across the UK, Ireland, and Germany represent a significant segment of the broader customer base. India's Digital Personal Data Protection Act, which has been enforced incrementally through 2025 and 2026, requires breach notification to affected individuals. Whether Revolut's obligations under that law apply to its Indian beta users is an open compliance question.

What Comes Next

This incident exposes a structural gap in how financial institutions respond to government data requests: email authentication alone is not sufficient authorization to release user records. Out-of-band verification, meaning a direct call or portal confirmation with the requesting agency, should be a mandatory step before any personal data changes hands. For users already affected, security best practice calls for treating home address information as fully compromised, updating contact details where possible, and staying alert to targeted phishing attempts that may reference personal crypto activity. A concurrent breach at hardware wallet manufacturer Trezor, where logistics provider ShipMonk exposed data for roughly 67,000 U.S. customers, signals that September 2026 represents a broader pressure point for the industry's approach to customer data security.