Data Breaches

Revolut Handed Passports And Transaction Histories To A Fake Government Request

Revolut Handed Passports And Transaction Histories To A Fake Government Request

Revolut sent customer passports, verification selfies, bank statements and complete transaction histories to criminals who asked for them by email. The requests arrived from a genuine government agency domain, carried valid domain authentication and were processed by Revolut staff as routine legal compliance.

The British fintech confirmed the breach publicly over the weekend of 13 and 14 September after notifying affected customers on 11 September. It has not said how many people were affected which government domain was abused or which country the authority behind that domain belongs to.

Passports, Selfies and Bitcoin History In One Disclosure

Customer notices shared by affected individuals reported by Alexander Martin at The Record, set out what was handed over:

  • Dates of birth, postal addresses, email addresses and phone numbers
  • Passport and driving licence copies
  • Facial verification selfies submitted during account onboarding
  • Bank statements and international bank account numbers
  • Withdrawal records and full transaction history, including Bitcoin activity

The victims were not picked at random. The Record reports that the fraudsters appear to have gone after high-net-worth individuals, many of them running crypto asset businesses. Mark Karpelès, former chief executive of the Mt. Gox bitcoin exchange, said he was among them. Cryptocurrency entrepreneur Marc Zeller wrote on X that he woke on Saturday to find “all my data leaked by Revolut”, shortly after Revolut had asked him for more documentation or his account would close within 20 days.

An Email Address Is Not A Zero-Day

Revolut described the incident to Infosecurity Magazine as a “sophisticated external impersonation scam”. Sophisticated is doing heavy lifting in that sentence. Someone obtained a working government mailbox and wrote polite requests from it. No malware, no exploit, no intrusion into Revolut infrastructure.

Hackers linked to Lapsus$ ran the same play against Apple, Meta and Discord in 2021 and 2022 using compromised law enforcement accounts to send forged emergency data requests. The FBI published an advisory in November 2024 warning that criminal forums were increasingly selling access to compromised government email accounts for exactly this purpose. Every financial institution that handles authority requests has had nearly two years of public notice.

Revolut says a limited number of customers were affected. It has published no figure. Firms that have finished counting normally publish the count and firms that have not normally say the investigation is open. Revolut has said neither and it declined to tell Recorded Future News whether an extortion demand exists. Claims circulating on Telegram that the domain was Italian and that the operation ran for six months come from an account that has since been suspended and remain unverified.

The EU Opened This Channel Wider Four Weeks Ago

Regulation (EU) 2023/1543 became applicable on 18 August 2026. It lets a judicial authority in one member state send a European Production Order straight to a service provider in another, skipping mutual legal assistance entirely. The provider has 10 days to produce the data or 8 hours where the issuing authority declares an emergency.

The companion Directive (EU) 2023/1544 required member states to put the receiving machinery in place by 18 February 2026. Most did not. On 27 March 2026 the European Commission sent letters of formal notice to 22 member states over incomplete transposition, Sweden and Finland among them. Denmark is not bound by the Regulation at all under its justice opt-out.

The 8-hour emergency clock is the part worth staring at. It exists so evidence does not vanish and it removes the one control that catches a forged request, the time to ring the issuing authority back on a number you looked up yourself. Revolut staff did what the process told them to do.

One Million Swedish Customers, Supervised From Vilnius

Revolut passed one million customers in Sweden this year according to Affärsvärlden, up from 800,000 in spring 2025, and the company has said it wants 3 million Swedish customers by 2030. Those accounts do not sit with a Swedish bank. Swedish customers bank with Revolut Bank UAB, licensed and supervised in Lithuania.

That changes where a complaint lands. Deposits fall under the Lithuanian deposit guarantee rather than Riksgälden, a point Realtid has made in response to Swedish comparison sites stating otherwise. If you received a Revolut notification on 11 September, check which Revolut entity holds your account before you file anything with Finansinspektionen or IMY.

Build The Verification Step Before The Next Request Arrives

Any organisation that can be served with a legal demand for customer data needs a verification step that does not depend on the email the demand arrived in. Four controls, in the order they can be put in place:

  1. Call back out of band. Ring the issuing authority on a number taken from its official site, never a number, address or link inside the request itself.
  2. Treat domain authentication as proof of the domain and nothing else. SPF, DKIM and DMARC confirm the mail left that domain. They say nothing about whether the person at the keyboard holds the office they claim.
  3. Log every authority request in one register. Requester, legal basis cited, data released, approver, timestamp. Central logging is what makes a victim count available on day one.
  4. Name a duty owner for emergency requests who has authority to refuse one and make refusal the default when the callback fails. Under the e-Evidence Regulation, a designated establishment has to be able to verify an order, not merely receive it.

Audit your own authority request register this week. If you cannot produce a count of requests received and data released over the past 12 months, you have the same gap Revolut has.

References

  1. Revolut Handed Customer Data to Fraudsters Using Government Email Account
  2. Revolut Confirms Data Breach Through Fake Government Requests
  3. FBI Advisory on Fraudulent Emergency Data Requests
  4. eEvidence Regulation: Key Compliance Takeaways for Service Providers by 2026
  5. Directive (EU) 2023/1544 on Designated Establishments for Gathering Electronic Evidence
  6. Commission Opens Infringement Procedures Against Member States for Failing to Transpose EU Directives

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.