Skip to content

Security1 publisher2 min readPublished

Revolut handed over passports to a rogue account inside a real government domain

The fraudulent request passed domain authentication because it genuinely came from the agency's mail domain, sent by an account the agency had not authorised. Revolut found out only when it called the agency to check.

The Watch · Security desk

Photograph accompanying Revolut handed over passports to a rogue account inside a real government domain
Photo: techcrunch.com

What happened

  • Revolut confirmed on September 12, 2026 that it disclosed sensitive customer data to an unauthorized third party. The fraudulent information requests came from an email address inside a real government agency's domain.
  • The attacker either created a rogue account in that agency's domain or compromised an existing one, then used it to submit what looked like a legitimate data request. Revolut staff processed it.
  • Per the notification TechCrunch reviewed, the disclosed records included birth dates, postal and email addresses, phone numbers and copies of identity documents including passports and driver's licenses.
  • Revolut learned the request was fraudulent only after it contacted the agency independently to verify it, and the agency confirmed it had never made the request.
  • Revolut says a limited number of customers were affected and were contacted immediately. It has not said how many.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any firm that fulfils agency data requests over email is reachable by the same account. Headers cannot separate an authorised sender from an unauthorised one inside the same domain.
  • decision Revolut made its verification call after the disclosure, and the workflow has to make that call before it. Genuine agency demands then wait longer for an answer.
  • constraint Other platforms cannot query their legal-request logs for the same sender while the agency is unnamed. A second victim would find out only through its own callback.
  • precedent Any platform holding the same customers is worth the same request. A full KYC file joined to identity-linked crypto transaction history is a ready-made package for impersonation or extortion of wealthy clients.

Domain authentication proves which domain a message left, not whether the person sending it was allowed to ask for anything. The account in this case sat inside the agency's own mail infrastructure, so the checks passed on their merits [16]. "The request came from an unauthorised email account sent directly using the official government agency's email domain," the notification said [3]. "As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request" [4].

Revolut's notification says the disclosed data may also have included verification selfies, account statements and transaction histories [8]. CoinDesk and Crypto Times report that the transaction histories covered Bitcoin [9]. The crypto security researcher ZachXBT, who posted about the notification to affected customers, assessed that the incident appeared to be targeted at high-net-worth users [10]. That assessment is his; Revolut has not said who the requests named.

Nothing was hacked. No systems were compromised, no malware was used, and Revolut says its servers were not accessed by an outsider and that customer funds were unaffected [14]. The company blocked the email address, alerted the agency, notified law enforcement and reported the incident to financial regulators [13].

Customers had the notification on September 11, a day before the confirmation reported on September 12 [2][1][17]. The timing lands while Revolut is arguing for regulatory standing: it holds conditional U.S. approval to become a national bank, is reportedly weighing a $200 billion IPO, and serves 80 million customers [15].

Revolut declined to name the agency involved or say which country or market was affected [12]. Security Affairs notes that naming the mailbox would let other regulated platforms search their own legal-request logs for the same sender [19].

What to watch

  • Whether Revolut or the agency names the mailbox, so other firms can search their own legal-request logs.
  • Whether a second regulated platform reports fulfilling a request from the same government domain.
  • Whether financial regulators respond by requiring out-of-band verification of law-enforcement and agency data requests.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories