Skip to content

Invest1 publisher2 min readPublished

Revolut released passports and Bitcoin histories on an email that passed domain authentication

The request came from an unauthorized account on a real government domain, and Revolut acted on it. The company calls the number of affected customers limited, and it declined to say how many or name the agency.

The Investor · Invest desk

Photograph accompanying Revolut released passports and Bitcoin histories on an email that passed domain authentication
Photo: techcrunch.com

What happened

  • Revolut handed a fraudulent requester passport copies, verification selfies and full Bitcoin transaction histories after a request arrived from a government agency's legitimate email domain.
  • The request came from an unauthorized account on the agency's official domain, and Revolut fulfilled it because the message carried valid domain authentication credentials.
  • The financial data released covers account statements with IBAN and wallet reference numbers, withdrawal records and full transaction history, including Bitcoin.
  • Revolut said a limited number of customers were affected, that it had blocked the email address, and that it alerted the agency, law enforcement and regulators.
  • ZachXBT said the incident appeared to target high-net-worth users, a concern given the surge in violent wrench attacks against known crypto holders.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Domain authentication tells a disclosure desk which mail server sent the message; entitlement to ask is a separate question, so a bank gating on that check alone has no control standing between a real government domain and a hijacked account inside it.
  • exposure The released file joins a named person at a known postal address to wallet references and a complete transaction history, giving anyone planning physical coercion both a target and an estimate of holdings.
  • precedent With the agency unnamed, every other firm that answers requests from that domain is working blind, and the same sender can try the next institution on the list.
  • decision Revolut now chooses whether to publish a customer count and the agency's name itself, or leave both to be established by regulators and IPO diligence.

An unauthorized account sent the request, and its domain credentials were valid. Both of those facts come from the same customer notification, circulated by the crypto investigator ZachXBT [2]. The check confirmed which domain the mail left. Whether the sender had authority to ask was a separate question [17].

The notice lists a copy of the passport or driver's licence and the selfie the customer provided for verification [5]. Those are the documents Revolut used to verify the customer's identity, and they are now with whoever sent the email [18]. Revolut said no biometric facial telemetry data was involved [7].

A Revolut spokesperson confirmed the breach to TechCrunch, describing it as "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information" [9]. The company said its systems and customer funds were unaffected [11]. The only quantity on the record is the word "limited" [20].

Revolut launched its euro-pegged EURR stablecoin this year and is weighing an IPO [15]. An incident with no stated size is one a diligence process will size for itself, and I would expect the count to be established there before it is published.

Two readings fit the record. In the first, one company's manual review failed, and confirming a requester through a published agency phone number closes the hole cheaply. In the second, the request channel is the soft spot at every regulated firm holding identity documents, and Revolut is one route among several open at once: Trezor's support-vendor breach widened to expose tens of thousands more customers, and X appeared to suffer a breach that flooded users with password resets [13][14].

Marc Zeller wrote on September 12, 2026: "Woke up to all my data leaked by @Revolut. Sharp reminder that KYC hasn't produced meaningful upside and has put many in harm's way." [16] The record supports the narrower version of that. The file exists because identity rules require it, and it moved because an email check was treated as proof of authority [17]. What would break the reading is a small count paired with a compromised mailbox inside the agency, which would make this a targeted operation against named individuals rather than a workflow any forger can run.

What to watch

  • Whether Revolut or a regulator names the impersonated agency, which would let peer firms check their own request logs.
  • Any count filed with a data protection regulator or disclosed in IPO documents that puts a number behind "limited".
  • Whether Revolut adds non-email confirmation of law-enforcement requesters, and whether rival banks say they already require it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories