Cookie Settings

    We use cookies to improve your experience. Essential and analytics cookies are automatically enabled. View cookie preferences

    Skip to main content
    Open bank vault releasing a passport, KYC selfie and a statement with Bitcoin addresses toward a gloved hand after a fake government email passed verification
    Data Breach
    Government Impersonation

    Revolut Data Breach: The Fake Gov Email That Passed DMARC

    September 14, 2026
    13 min read

    Nobody picked a lock. Somebody wrote a letter — and the letterhead was real.

    On 12 September 2026 Revolut began telling customers something no bank enjoys putting in writing: it had handed over their identity documents, their verification selfies, their statements and their Bitcoin transaction records — to a government request that turned out to be a fake. Not a spoofed lookalike domain. Not a Gmail with a badge in the signature. A request sent from an unauthorised account sitting inside a genuine agency's mail domain, which sailed through SPF, DKIM and DMARC like a man in a hi-vis vest walking past reception. Every automated check said the letter was authentic, because every automated check only ever checks the envelope.

    The Scheme in One Paragraph

    Regulated firms are legally obliged to answer lawful requests from police, tax authorities and regulators — often fast, often without telling the customer, sometimes without a warrant. That obligation is enforced by process, and the process is email. So the attacker skips the bank's firewall entirely and attacks the paperwork: get inside one government mailbox, write a request that looks like the hundred before it, and let compliance do the extraction for you. The data leaves through the front door, signed for, logged, entirely "legitimate".

    You don't rob a bank that has to give you the money if you ask correctly.

    Quick Answer

    Revolut told a limited group of customers that their identity files and financial records — Bitcoin transaction history included — were handed to an unauthorised third party who asked for them in the format of a law-enforcement request.

    The customer notice began circulating on 11 September 2026 and was reported the following day by TechCrunch, Crypto Briefing, CryptoSlate, crypto.news, The Crypto Times and ETHNews. All of them describe the same shape: Revolut's own systems intact, no stolen funds, no passwords or PINs, and — per on-chain investigator ZachXBT — a selection that looks skewed toward high-net-worth account holders. Revolut has not named the agency and has not published a figure for affected customers.

    • Exposed: identity documents, contact details, KYC verification selfies, account statements and transaction history — with Bitcoin addresses and payment references visible inside those statements.
    • Not exposed: passwords, PINs, card security codes, or access to funds. No money moved. Revolut's infrastructure was not hacked.
    • Do now: file a GDPR Article 15 subject access request asking specifically who received your data and when, treat every "security" call or mail as hostile, and move any address that appeared in a statement out of your long-term holdings.

    The vault held. Someone simply asked the vault politely, on the right paper.

    Data Breach Investigation Series

    This is Part 3 of 3. Different doors, same vault. Each breach exposes how the crypto industry fails to protect your data — whether through the side door or the front.

    Different doors, same vault:

    The Hard Truth

    Compliance did not fail at its job. It performed it exactly as designed — answer the state, answer it fast, ask questions later — and that design has no step for doubting the state.

    Refuse a genuine law-enforcement request and a regulated firm risks obstruction findings, fines and a very bad afternoon with its supervisor. Answer a fake one and, historically, almost nothing happens. The incentives point one way, the clock is always ticking, and "urgent" is the magic word in every language.

    So the weakest link in your bank's security isn't its code. It's the fear in its legal department.

    Anatomy of the Disclosure

    Strip the press releases away and the sequence is brutally simple. An unauthorised account on a genuine agency domain sends a data request. The mail passes SPF, DKIM and DMARC because it genuinely originates from that domain's authorised infrastructure. A human reads it, sees a real agency, sees a real authenticated sender, sees urgency, and complies.

    What left the building was not a marketing list. It was a dossier: government-issued ID, the selfie you took holding it, your address and phone, and a statement showing what you moved, when, to whom — Bitcoin references included.

    That combination is the one thing on-chain privacy cannot repair afterwards. Coins can be moved. A passport photo bound to a confirmed address cannot be unpublished.

    They didn't steal your Bitcoin. They stole the map to it, with your face stapled to the front.

    The Vocabulary, Decoded

    Six terms are doing all the heavy lifting in this story. Every one of them means something narrower than it sounds — and the gap between the two is where your data went.

    SPF, DKIM and DMARC

    What it actually is

    Three email standards that answer one question: was this message sent by infrastructure the domain owner authorised, and did it arrive unaltered? DMARC (RFC 7489) then checks that the visible From: address lines up with that result.

    What it is not

    Proof of authority. It authenticates a domain, never a person, and never their legal power to demand anything. A compromised or unauthorised account inside a real agency passes all three perfectly — the crypto is doing exactly what it was designed to do, and it was never designed to ask "is this officer real?"

    Emergency Data Request (EDR)

    What it actually is

    A channel that lets police obtain data without a warrant when someone's life is at immediate risk. Speed is the whole point; the paperwork catches up later.

    How it gets abused

    Fraudulent EDRs are documented, not theoretical. In 2022 reporting revealed that Apple and Meta had released user data to people using forged emergency requests, and US prosecutors in the Eastern District of New York later charged two men who used stolen police email access to pull records and then extorted the people behind them. The technique has a paper trail years long, and "someone will die if you wait for the warrant" remains the single most effective sentence in social engineering — because refusing it feels like committing a crime.

    Lawful request exemption

    What it actually is

    The legal basis that lets a bank disclose your data — and often stay silent about it — when a competent authority asks. Under UK and EU data protection law the duty to inform you can be restricted where telling you would prejudice an investigation.

    The trap inside it

    The same exemption that protects real investigations also silences the one person who would have spotted the fake instantly: you. Notification arrives after the data does.

    KYC verification selfie

    What it actually is

    The liveness photo you took holding your ID, proving the document and the face match.

    What it becomes when leaked

    A ready-made onboarding kit for opening accounts in your name, and a credible prop in a video call. Your password can be rotated in nine seconds. Your face cannot.

    Statement-level transaction history

    What it actually is

    A dated ledger of your fiat and crypto activity, including counterparties, references and — in Revolut's case — Bitcoin addresses appearing in the entries.

    Why it is the crown jewel

    One confirmed address is a thread, not a dot. Standard clustering heuristics — common-input-ownership and change-output detection — pull the rest of the wallet into view. Give an analyst one Bitcoin address tied to a named human and they will reconstruct a great deal of that human's financial life for free.

    Wrench attack

    What it actually is

    The oldest attack in cryptography: skip the encryption, apply pressure to the person holding the key. Extortion, home invasion, kidnapping.

    Why this leak feeds it

    The prerequisite is a shortlist of names, addresses and proven balances. This disclosure produced precisely that document — for customers who, per ZachXBT's read, look like they were selected for wealth rather than at random.

    Authentication proved the letter came from the building. Nobody checked whether the man inside had a right to be there.

    How They Find You

    Nobody targeted you personally at first. They targeted a mailbox, and you were in the filing cabinet behind it. Four ways the selection actually happens.

    One compromised government mailbox

    Agency email accounts are stolen the same way anyone's are: phishing, credential stuffing, reused passwords, an old contractor account nobody closed. Once inside, the attacker doesn't need to forge anything — the domain signs their mail for them.

    The mailbox that decided your privacy sits in an organisation your bank cannot audit and you will never be told the name of.

    Public wealth signals

    Founders, funds, loud portfolios, conference stages, court filings, leaked customer lists from earlier breaches. High-net-worth crypto holders are not hard to enumerate; most of them enumerated themselves.

    Selection for wealth is what turns a data request into a shopping list.

    The bank as index

    A neobank with tens of millions of customers is the most efficient identity resolver on earth: name, document, selfie, address and on-chain footprint in a single record, already verified and cross-checked.

    Aggregation is a feature until the day it becomes the payload.

    Silence as cover

    Because lawful requests can carry a non-disclosure component, the window between extraction and notification belongs entirely to the attacker. They knew before you did.

    The delay is not negligence. It is the design of the exemption they hijacked.

    What Lands In Your Inbox Next

    The disclosure is the raw material; the follow-up is the business model. These are composite reconstructions in the standard pattern of post-breach phishing, written the way they are actually written — the details are exactly what a leaked statement would let them use.

    The impersonated bank

    Revolut Security: we detected an unauthorised access attempt on your account linked to the recent regulatory disclosure. To secure your balances, verify your identity within 2 hours: rvlt-secure-verify[.]com/id

    Translation

    The breach is the pretext, and it is a true pretext — which is what makes it lethal. Real banks do not put a deadline and a link in the same sentence. They also never ask you to "verify identity" on a domain that isn't theirs. Two hours exists to stop you thinking.

    The fake officer

    Detective Constable [name], Financial Crime Unit. Your Revolut records form part of case ref FCU-2026-4471. Please confirm the Bitcoin addresses under your control so we can exclude them from the investigation.

    Translation

    Police do not ask victims to volunteer their full wallet inventory by email, and no genuine officer needs you to build their address list for them. This is asset discovery wearing a warrant card.

    The recovery specialist

    We act for affected Revolut customers. Because your KYC file was disclosed, you may be entitled to compensation and to have your data delisted. Initial data-removal fee: 0.05 BTC.

    Translation

    Nobody can delete a document that has already been handed to an unknown third party. Anyone charging you in Bitcoin to un-leak a passport is selling you the second robbery.

    The verification call

    [Video call] Hello, compliance team here — I can see your ID on file, could you confirm the six-digit code we've just sent so I can note your account as verified after the incident?

    Translation

    They have your document and your selfie, so the call opens with details only your bank should know. Any request for a code is an account takeover in progress, whatever the caller can recite about you.

    The quiet threat

    We hold your passport, address and BTC history from the Revolut file. Send 1.5 BTC to the address below within 48 hours or your holdings and home address are published.

    Translation

    Extortion built on public reporting: they may hold nothing at all and are betting on the news cycle. Paying confirms both your balance and your willingness to pay — the two facts you least want to sell.

    Seven Red Flags After Any Lawful-Request Leak

    • Inbound contact that already knows your breach status Anyone who opens with "because of the recent disclosure" is reading the news, not your file. Genuine incident notices arrive in the app first.
    • A deadline measured in hours Regulated firms give you days and named channels. Urgency is a manipulation instrument with a legal-sounding accent.
    • A link or a phone number inside the message Always navigate yourself: your own app, the number printed on your card, the agency's published switchboard. Never the callback they helpfully supplied.
    • Anyone asking which addresses you control No investigator, no bank and no exchange needs your self-declared wallet list. That question has exactly one purpose.
    • Requests for codes, seed words or screen sharing The code is the last lock standing after a document leak. Reading it aloud hands over the account you still have.
    • Offers to erase, delist or de-index your leaked data Impossible by construction. A paid "removal service" after an identity leak is a second scam pricing your panic.
    • Silence about which authority is involved Real correspondence names the body, the case reference and a verifiable contact route. Vagueness is not operational security; it is a tell.

    One rule survives all seven: you initiate the contact, or the contact is theirs to control.

    The Economics

    Fraud follows arithmetic. Three numbers explain why the letter approach beats the crowbar approach every single time.

    One mailbox, thousands of records

    Compromising a single agency account costs a phishing kit and patience. That one asset can be pointed at any regulated firm on the continent, repeatedly, until someone notices — and the request itself leaves no malware to detect.

    A dossier beats a database dump

    Bulk email lists are commodity goods. A verified identity bound to a proven crypto balance is bespoke: it enables account opening, credible impersonation, targeted extortion and physical targeting, all from one file.

    Selection beats volume

    Reporting describes a limited number of affected customers, apparently skewed toward the wealthy. Fewer victims, higher value each, less noise, slower detection. That is not a failed mass attack; that is the intended shape.

    Get alerted when a new scam drops

    No spam · Real investigations only

    How It Works, Step by Step

    Five stages, no exploit code anywhere in the chain.

    1

    1. Take the mailbox

    An unauthorised account on a genuine government domain is obtained — phished, bought, or simply never decommissioned.

    This is the only technically interesting step, and it happens somewhere you cannot audit.

    2

    2. Write like the regulator

    The request mirrors real ones: correct department, plausible case reference, statutory language, defined data fields, an urgency clause and, frequently, an instruction not to notify the customer.

    Format fluency is the credential. Compliance teams recognise the shape faster than the substance.

    3

    3. Pass every automated check

    SPF aligns, DKIM validates, DMARC reports pass. Nothing flags, because nothing is being forged.

    Worse, the log now records the sender as verified — so when someone finally reviews the file, the evidence agrees with the attacker.

    4

    4. Compliance delivers

    A human weighs obstruction risk against customer risk under time pressure and releases the file: documents, selfie, statements, transaction history.

    The failure is procedural, not technical — and procedure is exactly what nobody stress-tests.

    5

    5. Monetise the dossier

    Then comes the long tail: tailored phishing, impersonation, extortion, on-chain clustering from the disclosed addresses, and in the worst outcome a shortlist for physical coercion.

    The breach ends in a day. The exposure runs for as long as the documents are valid.

    How This Plays Out

    Three composite cases built from the documented pattern of post-disclosure fraud and on-chain analysis. Details are anonymised and combined; the mechanics are not invented.

    Each starts the same way — with an entirely genuine piece of information in a stranger's hands.

    The founder who got a very well-briefed phone call

    Forty hours after the notification, a caller quoted his document number, his registered address and a transfer from the previous month, then asked for the app code to "lock the account against the leak". He hung up, opened the app himself, and found no incident at all — only a live login prompt waiting for the code he nearly read out.

    "He knew everything my bank knows. That's exactly why I should have known he wasn't my bank."

    The address that unfolded into a wallet

    One Bitcoin address in a leaked statement was the whole opening. Two of his older payments had once been spent together in a single transaction, which is all common-input-ownership needs to declare them the same owner; change-output detection then walked that history forward year by year. Six days later an extortion mail quoted his balance to the decimal.

    "They didn't guess my holdings. My own bank statement introduced them."

    The recovery firm that only wanted a small fee

    A professional-looking outfit offered to have the disclosed KYC file "withdrawn and de-indexed" for 0.05 BTC up front, complete with case number and a countdown. The file, of course, was already sitting in an unknown inbox and could not be recalled by anyone at any price.

    "You cannot buy back a photograph. You can only stop paying for it."

    Methodology: composites assembled from public reporting on this incident (12 September 2026), the documented history of fraudulent emergency data requests, and standard Bitcoin clustering heuristics. No real customer, name or wallet is identified, and no figure here is presented as an official loss total.

    Why This Works On Careful People

    The people caught by this are not careless. They are correctly deferential to authority, and that is the exploit.

    Authority short-circuits scepticism

    A government letterhead moves the burden of proof onto the recipient. Compliance officers are paid to cooperate with the state, and hesitating feels like the risk rather than the safeguard.

    Accurate details buy trust instantly

    Once a caller can recite your document number and a real transaction, your brain stops auditing and starts assisting. Leaked precision is more persuasive than any forged badge.

    Breach fatigue dulls the response

    After years of notification emails, "your data was exposed" reads as background noise. This one is different in kind: the file that left is the same file you would use to prove that you are you.

    The clock is set to beat the paperwork

    The deadline is not there to fluster you. Checking your app, calling the number on your card, waiting for your bank's own incident notice — every one of those takes longer than two hours. Speed does not rush the victim; it outruns the systems that would have contradicted the story.

    Nobody was fooled by bad technology here. Everybody was fooled by good manners under time pressure.

    Five Rules That Actually Help

    • 1. File an Article 15 request and ask who received your data Under GDPR Article 15 you may ask for the personal data held about you and the recipients it was disclosed to. Ask precisely: which categories were released, on what date, to which body, and under what legal basis. A paper trail is the only leverage a customer has, and it forces the answer into writing.
    • 2. Retire every address that appeared in a statement Treat any disclosed Bitcoin address as permanently public and permanently attributed to you. Move long-term holdings to fresh addresses generated by a hardware wallet, avoid consolidating old and new coins in one transaction, and stop reusing addresses for incoming payments.
    • 3. Verify the authority, never the messenger For anything claiming to be police, tax or your bank: hang up, then reach the institution through a number you found yourself — the card, the official site, the published switchboard. If a request is genuine, it survives a callback. If it dies on verification, it was the whole attack.
    • 4. Harden what can still be rotated Your documents are static; your access is not. App-based or hardware second factors everywhere, no SMS codes on anything financial, a unique alias per financial service, a call-in passphrase where your provider supports one, and a fresh password on the mailbox that receives everything.
    • 5. Assume physical risk and act boring If your identity is now linked to a proven balance, stop broadcasting either. No portfolio screenshots, no public wallet claims, no addresses in your social profiles. Split holdings across wallets so no single seizure or single confession empties everything, and keep a small, obvious "decoy" balance for the moment somebody insists.

    Got a Suspicious Message?

    Use our AI-powered detector to analyze potential scams instantly.

    Key Takeaways

    • 1.Revolut was not hacked. It was asked — by an unauthorised account on a real government domain, and it answered.
    • 2.SPF, DKIM and DMARC authenticate a domain, never a person's authority. Passing all three proves the letter came from the building, nothing more.
    • 3.The payload was identity plus on-chain history: passport, selfie, address, statements, Bitcoin references. That combination cannot be rotated, only outlived.
    • 4.The disclosed addresses do not stay isolated. Clustering walks from one confirmed address to most of a wallet, and a known wallet beside a known home address stops being a privacy problem and becomes a physical one.
    • 5.Your defence is procedural too: Article 15 to find out what left, fresh addresses for what remains, and never verifying anyone through a channel they chose for you.

    The letter was real.

    The authority wasn't.

    Frequently Asked Questions

    Share This Article

    Sources & Citations

    Research for this investigation compiled from publicly available blockchain data, security reports, and community documentation.

    Verification: All blockchain transactions and addresses referenced in this article can be independently verified through the linked blockchain explorers. We encourage readers to conduct their own verification.

    Methodology: Every case requires at least three independent sources plus verifiable on-chain evidence before publication. Full standards: /methodology

    Legal notice: This assessment is based on publicly available data, including on-chain records, official statements and reported incidents. It is journalistic and educational analysis, not legal advice, an accusation of criminal conduct or a court finding. Named companies, projects, domains, wallets and individuals are described as reported by the cited sources; a company name may appear because fraudsters impersonated it, not because the company did anything wrong. If you believe something is inaccurate or out of date, write to cryptostrapon@proton.me and we will correct it and log the change. Editorial policy