Revolut has confirmed that it disclosed sensitive customer data to an unauthorised third party who posed as a government agency. The company told TechCrunch on 12 September 2026 that it had identified a "sophisticated external impersonation scam" in which the requester used a legitimate government agency email domain to submit fraudulent requests for information.

Revolut says a limited number of customers were affected, that its systems and customer funds were not, and that it has blocked the address and alerted the agency concerned, law enforcement and regulators. It has not said how many customers, in which countries, or which agency.

The incident became public when crypto investigator ZachXBT circulated the notification Revolut sent to affected customers, and said the targets appeared to be wealthy users.

What was handed over

According to the customer notice as reported by Decrypt, the disclosed material could include:

  • Identity details: full name, date of birth and occupation.
  • Contact details: home address, email address and phone number.
  • Documents: a copy of the customer's passport or driving licence, and the selfie taken for identity verification.
  • Financial records: account statements with IBAN and wallet reference numbers, withdrawal records, and full transaction history, including bitcoin.

Revolut draws a line between the selfie, which was included, and biometric facial telemetry, which it says was not.

Read the list again. It is, almost item for item, what a regulated financial company asks a new customer to provide at sign-up. Scans of identity documents are already traded in bulk; this set comes attached to account records and a history of crypto activity.

Why every check passed

Email has three standard sender checks. SPF lists which servers may send mail for a domain. DKIM has the sending domain sign each message with its own key. DMARC ties those results to the address the reader actually sees, and tells receiving servers what to do when they fail.

All three answer the same question: did this message really come from the domain it claims? According to the notice, Revolut's request came from an unauthorised account using the agency's official domain. So the honest answer to that question was yes. The checks did their job.

What none of them can say is who controls that mailbox, or whether that person has any authority to demand a customer's records. That is a question about the requester, not the message, and it cannot be answered from inside the email.

A known pattern

In November 2024 the FBI warned US companies that criminals were likely gaining access to compromised US and foreign government email addresses and using them to send fraudulent emergency data requests, exposing customers' personal information. KrebsOnSecurity reported at the time that sellers on crime forums were offering such requests for between 1,000 and 3,000 dollars per successful request, and claiming government email access in more than 25 countries.

The same reporting cited Kodex, a company that vets law enforcement requests on behalf of platforms, as saying that about 30 per cent of the 1,597 emergency requests it had processed in a year failed a second-level verification.

Revolut has not described its case as an emergency request. The mechanism, a genuine government mailbox asking a company for a customer's records, is the one the FBI described.

What verifying a requester looks like

Companies that receive official requests at scale tend to verify the requester through a route that does not depend on the email. Common controls include calling the agency back on a number taken from an independent directory rather than from the message, requiring requests through a portal where officials hold vetted accounts, checking that the agency has any jurisdiction over the customer concerned, and escalating any request for identity documents and complete account histories.

Revolut has not said which of these it applies, or which checks the requests passed.

Why the targets matter

ZachXBT's concern is physical. A record showing that someone holds crypto, with a verified home address and a photograph of their face, is raw material for so-called wrench attacks, in which criminals coerce holders in person. The Record, citing blockchain security firm CertiK, reported this month that such attacks have risen 33 per cent year on year.

Trezor's breach at its fulfilment provider raised the same risk from a shipping list. This one comes with transaction histories.

If you received the notice

  • Assume anyone contacting you may already know your address, documents and account history, and treat unsolicited contact about your account as hostile.
  • Watch for new accounts opened in your name, using a credit freeze or monitoring where that is available.
  • Ask your mobile carrier about locking your number, since phone-based account recovery is an obvious next step for someone holding your identity documents.
  • Verify any contact that claims to be from Revolut inside the app itself, not through a link or a phone call.

What is not established

  • Which agency's domain was used, and in which country.
  • How the requester got an account on that domain: a compromise, an insider, or an account created some other way.
  • How many customers were affected, and in which markets.
  • How long the requests went on, and how many were fulfilled before they were stopped.
  • Whether the agency has disclosed a breach of its own email.
  • What verification the requests went through at Revolut.