Illustrative image generated with AI
Revolut Released Customer KYC Records After Fake Government Request Passed Email Checks
Revolut disclosed customer KYC records after a fake government request passed email checks, exposing passports, selfies and transaction histories.
Text generated by artificial intelligence, published without human review. AI transparency
A trusted government identity concealed an unauthorized request
Revolut confirmed on September 12, 2026 that it disclosed sensitive customer records to an unauthorized party after receiving a fraudulent government data request.
Customer notifications began circulating on September 11, according to TechCrunch. Reporting on the incident indicates that the message came through infrastructure belonging to a genuine government agency and carried valid credentials associated with its official domain.
Those characteristics allowed the email to pass Revolut’s authentication checks. Employees consequently treated it as a legitimate legal or regulatory request and supplied the requested customer information.
Revolut later contacted the agency through an independent channel. The agency said it had not issued the request, exposing the sender as unauthorized—but only after the records had been released.
This was not a conventional intrusion into Revolut. There is no reported malware infection, exploitation of a software vulnerability, unauthorized access to company servers, or compromise of customer balances. Instead, the attacker abused a trusted external identity to obtain data through an apparently valid administrative process.
The government agency involved has not been named.
Passports, selfies and transaction histories were potentially exposed
The disclosed records potentially covered much of the information Revolut collects for identity verification, customer due diligence and financial monitoring.
The affected data may have included:
- Full names, dates of birth and occupations.
- Postal addresses, email addresses and telephone numbers.
- Copies of passports or driver’s licences.
- Customer selfies submitted during identity verification.
- Account statements containing IBANs, account status and account-opening dates.
- Wallet reference numbers and withdrawal records.
- Complete transaction histories, including Bitcoin transactions.
Revolut said biometric facial-telemetry data was not compromised. That distinction matters technically: a verification selfie is an image, while biometric telemetry generally refers to measurements or templates generated by systems that analyze physical characteristics.
Nevertheless, the disclosed images remain sensitive. A passport or driving licence paired with a matching selfie can help criminals impersonate a customer, defeat manual identity reviews, create fraudulent accounts, or make later social-engineering attempts appear credible.
The financial information adds another layer of risk. Transaction histories can reveal counterparties, spending patterns, account activity and indicators of personal wealth. Bitcoin records may connect cryptocurrency activity with a verified real-world identity, enabling attackers to build detailed profiles of individual customers.
There is no evidence in the disclosed information that funds were stolen. The absence of immediate financial theft, however, does not eliminate longer-term risks such as identity fraud, extortion and highly personalized phishing.
Email authentication verified the domain, not the sender’s authority
The available evidence points to a failure in request validation rather than a failure of Revolut’s internal access controls.
The attacker appears to have gained the ability to send messages from inside the government agency’s legitimate domain environment. Two possible routes have been identified: an existing agency account may have been compromised, or an unauthorized account may have been created within that environment. It is not known which occurred.
Because the message traveled through official infrastructure, it could satisfy the technical checks Revolut used to assess incoming email. Controls such as SPF, DKIM and DMARC can help establish whether a message is authorized by, signed for, or aligned with a particular domain.
They cannot establish legal authority.
A correctly authenticated email may still come from a compromised mailbox, a malicious insider, or an account created without proper approval. Domain authentication answers questions about message handling and domain alignment; it does not prove that the person behind the account is empowered to demand customer records.
In this case, independent verification with the agency revealed the deception. The decisive weakness was that this confirmation occurred after disclosure rather than before it.
No CVE identifier, exploit or malware family is associated with the incident. There are also no affected software versions because the event was not attributed to a product vulnerability.
The customer count and geographic scope remain undisclosed
Revolut described the affected population as a limited number of customers and said it contacted those individuals directly. It has not disclosed the exact number, the countries involved, or whether the requests were restricted to one market.
Crypto security researcher ZachXBT assessed that the operation appeared to target high-net-worth customers. That assessment has not been confirmed by Revolut, but it is consistent with the value of the requested information.
A targeted operator could use account statements and cryptocurrency histories to identify wealthy individuals, estimate their holdings, map their financial relationships, and select them for follow-on fraud or coercion. Contact details and identity documents would then provide the material needed to make those approaches more convincing.
The attacker’s identity is unknown. It is also unclear whether the records were requested for direct financial fraud, intelligence gathering, extortion, account impersonation, or another purpose.
Revolut serves 80 million customers worldwide. The incident therefore affects only a small reported portion of its user base, but the individual impact could be severe because each exposed package combines identity proof, contact channels and financial activity.
The disclosure also arrives while Revolut is pursuing greater regulatory standing. The company had recently received conditional approval to become a national bank in the United States and was reportedly considering an initial public offering at a valuation of $200 billion.
Revolut blocked the sender and notified authorities
Revolut said its systems and customer funds were not affected. Following the discovery, the company:
- Blocked the email address used to submit the request.
- Alerted the government agency.
- Notified law enforcement.
- Reported the incident to financial regulators.
- Contacted affected customers directly.
Blocking one address may stop further requests from that specific mailbox, but it does not establish whether other accounts within the same agency environment were abused. The undisclosed identity of the agency also limits the ability of other financial institutions to review their own legal-request records for messages from the same source.
Revolut has not published the sender’s address or other technical indicators. No evidence has been disclosed showing that similar requests reached other regulated companies.
Financial institutions handling government demands should preserve request logs and search for unusual or newly observed agency mailboxes. Requests seeking identity documents, verification selfies, complete statements, wallet identifiers or cryptocurrency histories warrant additional scrutiny because they combine unusually sensitive categories of information.
High-risk disclosures should require out-of-band confirmation using a previously established contact method—not a telephone number, link or contact supplied in the incoming message. Institutions can also maintain directories of authorized agency requesters and require secondary approval before releasing extensive customer files.
Affected customers should expect convincing impersonation attempts
Customers notified by Revolut should treat their exposed identity and financial information as durable. Passports, transaction histories and verification images cannot be made secret again simply by changing a password.
Affected individuals should scrutinize messages or calls that reference genuine Revolut activity, Bitcoin transactions, account-opening information, addresses or other accurate details. Knowledge of those facts does not prove that the caller represents Revolut, a regulator or a law-enforcement agency.
Customers should independently open the official Revolut application or use established support channels rather than following links in unsolicited messages. They should also monitor accounts for unauthorized activity and watch for attempts to open financial products in their names.
The likely danger is not a replay of the original request. It is the use of authentic KYC data to make the next fraud attempt look legitimate.
Sources
This article is an original reworking based on the sources below.
