Desk live·
ForensicPost
Breaches/Identity/File 26-0912

Revolut Handed Customer Files to Someone Writing From a Real Government Agency’s Domain

The fintech confirmed on 12 September that fraudulent data requests sent from a legitimate government email domain had drawn passports, selfies, IBANs and full transaction histories for a limited number of customers. A 10,000-bitcoin demand followed. Revolut did not name the agency.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomLondonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetRevolut customers
ActorUnattributed
D. Kennedy9 min readConfidence: medium3 sources reviewed

Revolut confirmed on 12 September 2026, after a customer notice was posted by the researcher ZachXBT, that an unauthorised third party had used a legitimate government agency’s email domain to submit fraudulent requests for customer information, and that the company had answered them. The data released for what Revolut called a very limited group of customers included names, birth dates, addresses, occupations, copies of passports and driving licences, onboarding selfies, IBANs, account statements and full transaction histories including cryptocurrency activity. Funds and systems were not touched, the company said.

Revolut said it had alerted the agency that its identity was being abused, along with law enforcement, data protection and financial regulators. It named none of them. The Register reported that individuals claiming responsibility demanded 10,000 bitcoin, about $782 million, and threatened daily leaks. Revolut did not acknowledge the demand.

The Request Channel As The Attack Surface

Every regulated financial firm runs a desk that answers lawful requests from police and regulators. The desk is built to comply quickly, and its check on a request is largely that it comes from the right domain. An attacker who can send from a government domain, whether through a compromised mailbox or a forwarding rule, inherits that trust. The corpus filed the same shape at 26-0713, where the support ticket was the breach; here the ticket came with a badge.

What Was Released Is The Onboarding File

The fields describe a complete know-your-customer record: the identity document, the selfie taken to match it, the bank details and the movement of money. The reissuance line the corpus draws at 26-0324 applies to most of it. A passport can be replaced; a selfie cannot, and neither can a year of transactions. For customers with cryptocurrency activity in the record, the file is also a list of people known to hold bearer assets, the position recorded at 25-0530.

Limited, Unnamed, And Then Again

The count is not published. The agency is not named. The demand is an attacker’s claim. And on 25 September The Register reported a second, separate Revolut customer-data incident in the same month, tied to the brokerage partner DriveWealth. The file is graded medium on the gaps, not on the fact, which the company confirmed in its own words.

How we reported this

Compiled from Revolut’s customer notice and statements as reported, listed below. The agency, the jurisdiction and the count were not disclosed. The bitcoin demand is an attacker claim reported by one outlet and is carried as such. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Revolut confirms customer data breach through fake government requestsTechCrunch
  2. Revolut falls for fake government requests, hands over customer dataThe Register
  3. Revolut Confirms Data Breach Through Fake Government RequestsInfosecurity Magazine
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary