A single email dressed up as an official government request slipped past Revolut's checks — and the bank handed over a batch of customer data in response. Only afterward, when Revolut contacted the agency directly, did it learn the request had never been sent by anyone there.
The breach is narrow but nasty. Whoever received the reply now holds passports and driving licenses, verification selfies, home addresses, dates of birth, IBANs and, separately, a full history of Bitcoin activity — wallet references, withdrawal amounts, complete transaction records. Facial biometric telemetry wasn't part of the haul, which Revolut says is a distinct category from the verification selfies that were exposed.
The failure sat in the vetting process itself. The forged email carried credentials that passed Revolut's internal authentication as a genuine official request — convincing enough on paper, fake underneath. The bank released the data first and caught the forgery only later, after checking with the agency directly.
No money moved. Account balances stayed untouched. But a passport paired with a crypto transaction history is exactly the bait scammers need for targeted follow-up attacks — the classic play of posing as an exchange, a bank or "support" to squeeze a crypto holder for access. On-chain investigator ZachXBT flagged that the leak looked narrow rather than mass, hinting the attacker may have gone after high-balance accounts specifically.
Revolut says it has blocked the compromised email address across its systems, notified affected customers on September 11, alerted regulators, and warned the impersonated agency that its name was being used in fraudulent mail. It still hasn't said how many customers were caught up in the leak — the one number everyone actually wants.



