Contents

Revolut Handed Over Passports, Selfies and Full Bitcoin Histories to a Fake Government Email

 

Ethical Hacking Complete Course Zero to Expert

Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.

→ Take the full course
 
Contents

Your passport, your selfie, your IBAN and your full Bitcoin history went out because someone emailed from the right domain. Revolut handed it over. The FBI warned companies about this exact route in 2024.

On Friday evening, 11 September, Revolut customers received an email with the subject line “Urgent security update about your Revolut account”. Inside was the news that their personal records had gone to an unauthorised third party. This did not start with malware or a stolen password. Someone sent a request for customer information from an email account running on the official domain of a government agency, and the bank answered it.

Revolut put it in writing to the people it affected. The request originated from an unauthorised email account created directly within an official government authority’s domain infrastructure, and the communication carried genuine domain authentication credentials, so the bank fulfilled it under the reasonable belief that it was an authentic government agency request.

The account was created inside the government’s own mail system. Domain authentication, the set of checks that tells a receiving mail server whether a message genuinely came from the domain it claims, passed cleanly, because the message genuinely did come from that domain. Domain authentication proves the domain. It never proved the person behind the keyboard. From that point on, the technical controls Revolut had were working exactly as designed, and the data still walked out.

Here is what went out, according to the notification Revolut sent to the people it affected:

  • → Full name, date of birth and occupation
  • → Postal address, email address and telephone number
  • → A copy of the passport or the driving licence
  • → The facial verification selfie taken during onboarding
  • → Account statements with IBAN, account status, opening date and wallet reference number
  • → Withdrawal records
  • → The full transaction history, including Bitcoin

Revolut adds in the same message that no biometric facial telemetry was involved, only the image itself. That distinction carries weight in law. It carries a lot less in practice, because a passport scan and a photo of the same face is exactly what a verification flow asks you for.

That is not a list of contact details. That is the full set a bank collects to prove you are who you say you are, and it is enough for someone else to pass as you somewhere it counts.

The customers did nothing wrong. They did not reuse a password and they did not install anything. They uploaded a passport photo years ago because the law required it, and that file was still sitting there, waiting for someone to ask for it in the right format.

Revolut only found out because it went back and checked. The bank contacted the agency independently to validate the request, and in doing so had to tell that agency there was an unauthorised account operating inside its own domain. The government body did not know. Revolut blocked the address across its internal systems after that and notified regulators. The data was already gone.

One of the people who received the notification was Mark Karpelès, the former chief executive of Mt. Gox, who published his copy of the letter in public. His point is the one that matters beyond his own account. Revolut will not name the agency whose domain was used, and while that name stays secret, no other bank, exchange or broker can search its own legal-request logs for messages from the same mailbox. If that account sent requests to five other companies last month, those five companies have no way of knowing it happened. The silence protects one bank and leaves the other firms that answer these requests without a way to check themselves.

It did not end with the disclosure either. According to reporting on the group’s own Telegram channel, the people behind the requests have started publishing the material, with identity documents and verification selfies in the first batch, and they are demanding payment. The claim is that the releases will continue daily until Revolut pays for leaking its customers. Those documents have not been independently verified and Revolut has not responded to them. A passport scan and a verification selfie of the same person, published side by side, cannot be revoked and cannot be reissued the way a password can.

None of this is new.

In March 2022, security reporter Brian Krebs documented how criminals were buying access to hacked police and government email accounts and using them to send fake emergency data requests. That is a legal route which lets law enforcement obtain subscriber information without a warrant when someone’s life is believed to be in immediate danger. Because the claim is an emergency, there is no court review and no waiting period, and the company receiving it has to decide in minutes whether to hand the data over or risk being the reason somebody died. Apple and Meta both gave up customer information in response to forged requests. Discord confirmed it had answered one from a law enforcement account that turned out to have been compromised, and said it verifies that requests come from legitimate sources before it complies. One of the hackers Krebs interviewed put it differently and claimed Discord answers these in thirty minutes to an hour. The seller who advertised that service in April 2021 was fourteen years old and charged between $100 and $250 per request. Access to send mail from an Argentine federal agency’s domain went for $150, and the seller said openly that the buyer would not get the login.

In November 2024 the FBI put out a private industry notification about this exact technique, numbered 20241104-001, titled “Easy Access to Information for Conducting Fraudulent Emergency Data Requests”. That August, a seller on a criminal forum had advertised high quality .gov emails for espionage, social engineering and data extortion, offering to walk buyers through the emergency request process and to sell stolen subpoena documents so the buyer could pose as a law officer. In March that year another seller claimed to hold government email accounts from more than 25 countries. Go back to August 2023 and someone was teaching people how to write and submit their own emergency data requests for $100. The FBI’s advice to companies was to look hard at the legal codes cited in a request, since a foreign agency has no business quoting US Title Code, and where doubt remained, to contact the sender and the originating authority before answering.

Revolut did that last part. It did it after the data had already gone out.

Some companies turn these requests down. In March 2024 a forged request landed at PayPal, dressed up as a Mutual Legal Assistance Treaty request about a live child trafficking investigation, complete with a case number and a legal code for verification. PayPal refused it.

The volume is what makes this work. In the second half of 2023, Verizon alone received 36,033 emergency requests from US law enforcement, counted separately from the 7,205 that came from emergency call centres, on top of 61,120 subpoenas and 21,718 warrants. It produced no records for roughly 10 percent of all demands, and its own list of reasons is mostly about records it never had: wrong provider, data it does not collect, data past its retention period. What it did hold, it mostly handed over. That is one company, over six months, and the review teams work through that queue under the clock, because urgency is the point of the form.

A closer pattern sits in Revolut’s own history, and it does not take four years of hindsight to see it. In late February 2026, a crypto trader said a former Revolut employee had pulled his KYC file out of internal systems, approached family members who also used the app, and demanded a ransom in crypto to keep it offline. Revolut confirmed the case, reported the man to law enforcement, and said its security systems had worked as intended. That was seven months ago. KYC data, a ransom demand, and the message that the systems held.

Go back further and the shape repeats. In September 2022, Revolut lost the personal data of 50,150 customers to a social engineering attack, and Lithuania’s State Data Protection Inspectorate opened an investigation into it. The bank led with a percentage at the time, 0.16 percent of its customers, which lands very differently than fifty thousand people.

This time Revolut has published no number at all. It will not say which country, over what period the requests arrived, or which agency’s domain was used. It calls the group of affected customers very limited. ZachXBT, the on-chain investigator who first published the notification, says the incident looks small in size but aimed at high net worth users, which makes it a selection rather than a sweep. Somebody knew which names to ask for before asking. Those statements may be entirely true. None of them can be checked from the outside. Eight days before the notification emails went out, on 3 September, Revolut received conditional approval from the US Office of the Comptroller of the Currency to form a national bank.

This is not really a story about one bank. The services that made you photograph your passport are holding the same file, and each of them has a process for answering requests from law enforcement. Crypto exchanges, brokers, betting sites, mobile operators, rental platforms, insurers. In those companies the process comes down to a person reading an email and deciding whether it looks official enough, under time pressure, with someone’s life named in the subject line.

What you can do about it:

  • → Write down the services that hold a scan of your passport or ID. The list will be longer than you think
  • → Close the accounts you no longer use, and ask in writing for the identity documents to be deleted with them
  • → Put a passkey or a hardware key on the accounts that matter, so a leaked identity file on its own is not enough to get in
  • → Treat any call or email that quotes account details only your bank should know as suspect, and verify it by calling the number printed on your card
  • → Watch for credit applications in your name, not only for logins on your existing accounts
  • → When a service asks for a fresh identity photo, ask how long it is kept and who is allowed to request it

Want to find out how much of your own identity is already sitting in someone else’s database, waiting for the right email to ask?

My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.

Join my complete ethical hacking course

Hacking is not a hobby but a way of life.

Sources:

FBI Private Industry Notification 20241104-001 | Verizon US Transparency Report, 2nd half 2023 | OCC Corporate Decision #1390

 
NEWSLETTER

Stay updated

Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.

By Bulls Eye

Jolanda de koff • emaildonate

My name is Jolanda de Koff and on the internet, I'm also known as Bulls Eye. Ethical Hacker, Penetration tester, Researcher, Programmer, Self Learner, and forever n00b. Not necessarily in that order. Like to make my own hacking tools and I sometimes share them with you. "You can create art & beauty with a computer and Hacking is not a hobby but a way of life ...

I ♥ open-source and Linux