Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 14, 2026 · 7 min read

Revolut Leaked ID Docs to a Fake Government Email

Nobody breached Revolut. Somebody asked, from inside a real government agency's email domain, and Revolut answered with passports, verification selfies, home addresses and complete transaction histories.

The disclosure landed on September 12, 2026, in a notice to a group of customers Revolut describes only as "limited." What it describes is not an intrusion. A request arrived through the ordinary channel regulated firms use to answer law enforcement, from an address that passed every check because the domain genuinely belonged to a government agency. TechCrunch published Revolut's confirmation the same day.

Key Takeaways

  • Revolut confirmed on September 12, 2026 "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."
  • The disclosed records covered birth dates, postal and email addresses, phone numbers, copies of passports and driver's licenses, verification selfies, account statements and transaction histories.
  • Revolut called the number of affected customers "limited" without publishing a figure, and has not named the agency whose mailbox was used.
  • Investigator ZachXBT, who surfaced the notice, said the incident looked targeted at high net worth users.
  • The FBI warned companies in November 2024 that credentials for police and government mailboxes were selling openly on criminal forums.
An official looking government letterhead envelope lying on a wooden desk next to a smartphone displaying a banking app, softly lit by daylight from a window

What Exactly Did Revolut Hand Over?

Revolut handed over a complete identity file rather than a contact record, down to the onboarding selfie and every transaction on the account. For customers who moved crypto, CoinDesk reported that Bitcoin transaction records were part of the exposure, alongside the postal address of the person who made them.

An on chain history alone is pseudonymous. Joined to a verified home address it becomes a list of targets ranked by balance, which is why ZachXBT read the victim selection as deliberate. Revolut says its systems were never compromised and customer funds are untouched. Both can be true while the outcome beats most intrusions: an intruder takes whatever the database holds, a requester gets the dossier a compliance team assembled about one named person.

How Does a Fake Government Request Work?

An emergency data request lets a government agency ask a company for user data without a warrant when someone is believed to be in immediate danger. Brian Krebs documented the abuse in March 2022, when Apple, Meta, Discord and Snap were approached with forged requests and several complied.

The mechanics have barely changed. Someone takes over a police mailbox, usually with infostealer credentials resold on a forum. Inside sit real legal requests, which become templates: correct letterhead, correct case reference format, correct urgency. A member of the group calling itself the Recursion Team sold a "Warrant/subpoena service (get law enforcement data from any service)" for $100 to $250 per request.

By November 2024 the FBI was warning U.S. firms directly, after sellers began offering government mailboxes with coaching on how to use them, as Krebs and SecurityWeek both reported. Revolut is the next chapter, with the target moved from a chat platform to a bank.

Why Didn't Email Authentication Catch It?

Because SPF, DKIM and DMARC were all reporting accurately. Those protocols answer one question, defined in RFC 7489: was this message sent by infrastructure the domain owner authorises? When the attacker operates a real mailbox on that domain, the honest answer is yes.

The legal side is no firmer. In the United States, 18 U.S.C. 2702(b)(8) permits a provider to disclose in good faith when it believes an emergency involving danger of death exists. Permits, not compels. No judge reviews it, and the whole verification burden lands on whoever reads the message.

Why ID Documents and Selfies Are the Worst Payload

A password rotates in 30 seconds. A passport number stays fixed until the document expires, five to ten years out for most holders, and the face in the verification selfie never expires at all. That permanence is what makes this set worth more than a credential dump, as with the 153 million driver's license scans stolen from IDScan two weeks ago.

Three abuses follow. The document and selfie pair satisfies onboarding at other financial services, most of which accept an uploaded image and a liveness step a recorded face can survive. Birth date, address and phone number is the standard script for a SIM swap. And account recovery at nearly every major provider, Gmail included, leans on some mix of those facts when a reset goes wrong.

What "Limited" and an Unnamed Agency Leave Unanswered

Revolut has published no victim count, no date range for the requests, and no name for the agency whose domain was used. Without a count, nobody can tell whether "limited" means nine people or nine hundred. Without the agency name, every other firm that answers requests from that same domain is still exposed and does not know it. That is a shared infrastructure problem, and the case for mandatory public reporting behind the Washington attorney general's finding that 8 million residents were hit by breaches in 2025.

Article 33 of the GDPR requires notifying the supervisory authority within 72 hours of becoming aware of a personal data breach. Revolut says it notified customers, the agency, law enforcement and regulators. It has not said when it became aware.

What This Means for Your Inbox

The trust anchor that failed here was an email domain, and your inbox rests on the same anchor. Every instinct you were taught for spotting a hostile message assumes the attacker cannot get inside a legitimate domain: check the sender, hover the link, look for the misspelling. None of that survives mail from a mailbox that really belongs to the organisation on the envelope. Government systems get compromised routinely, as the Thomson Reuters C-Track breach affecting courts in 12 states showed.

For affected customers, the second wave is the likelier harm. Whoever holds those files also holds a verified email address, a real balance and a scanned passport to quote from. Nothing built on that material will read like phishing, because the details all check out. The UK's National Cyber Security Centre publishes guidance on the phishing wave that follows a breach for that reason. Accuracy is not authenticity.

What Should a Revolut Customer Do Now?

  • Verify every Revolut message inside the app. Do not act on links or numbers that arrived by email, including any explaining this incident.
  • Add a port out PIN with your mobile carrier. Birth date, address and number are the exact inputs a SIM swap needs.
  • Move account recovery onto hardware. A security key does not care who knows your postal code.
  • File a subject access request. Article 15 of the GDPR entitles you to know what was disclosed about you and to whom, the only route to a number rather than "limited."
  • If you hold crypto, treat the address exposure as physical. Transaction history joined to a home address is a targeting dossier. The FTC's IdentityTheft.gov covers the identity side.

Looking Ahead

Most coverage frames this as Revolut falling for a scam. The more uncomfortable reading is that the process worked as designed: mail arrives, the domain checks out, data goes out. Every regulated fintech is running roughly that intake right now.

Fixing it means refusing to treat a message as proof: call the agency back on a number from its published directory rather than the signature block, and cap what a single urgent request can extract before a second reviewer signs off. No plausible emergency requires a verification selfie and 18 months of statements in one reply. The FBI's 2024 notification recommended that callback two years before Revolut needed it.

Watch whether a regulator sets a verification standard for these requests, and whether the unnamed agency ever confirms the compromise. Until it does, that domain is a working key to somebody else's customer files.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.