BREAKING
Sep 20Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-BooksSep 19The Senate Needed 60 Votes to Give Crypto a Rulebook and Got 49. The CFTC Needed Zero, and Just Filed One With the White House.Sep 18The SEC Just Legalized Trading Apple Stock on Uniswap. The $3 Billion of Tokenized Stocks That Already Exist Don't Qualify.Sep 17Two Robinhood Engineers Front-Ran Their Own Company's Token Listings on Hyperliquid. They Made $50K Each. They're Facing 30 Years.Sep 16The Democrats Who Helped Write the CLARITY Act Just Voted to Kill It. 49-50. Crypto's Senate Bill Is Dead for 2026.Sep 15Balancer's CEO Just Asked Token Holders to Vote the Protocol Dead. Its $9M Treasury Is Worth More Than Its Own Token.Sep 14Trump Made $1.4 Billion on Crypto Last Year. Republicans Just Sent Democrats a 'Final Offer' That Makes Him Give Up Control of It.Sep 13Someone Emailed Revolut From a Real Government Domain. Revolut Sent Back Passports and Bitcoin Histories.Sep 12FTX Creditors Got Up to 120% of Their Money Back. SBF Just Told the Supreme Court That's Why He's Innocent.Sep 11They Pointed AI Agents at Bitcoin's Encryption. Eight Weeks Later, Cracking It Got 86% Cheaper.Sep 20Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-BooksSep 19The Senate Needed 60 Votes to Give Crypto a Rulebook and Got 49. The CFTC Needed Zero, and Just Filed One With the White House.Sep 18The SEC Just Legalized Trading Apple Stock on Uniswap. The $3 Billion of Tokenized Stocks That Already Exist Don't Qualify.Sep 17Two Robinhood Engineers Front-Ran Their Own Company's Token Listings on Hyperliquid. They Made $50K Each. They're Facing 30 Years.Sep 16The Democrats Who Helped Write the CLARITY Act Just Voted to Kill It. 49-50. Crypto's Senate Bill Is Dead for 2026.Sep 15Balancer's CEO Just Asked Token Holders to Vote the Protocol Dead. Its $9M Treasury Is Worth More Than Its Own Token.Sep 14Trump Made $1.4 Billion on Crypto Last Year. Republicans Just Sent Democrats a 'Final Offer' That Makes Him Give Up Control of It.Sep 13Someone Emailed Revolut From a Real Government Domain. Revolut Sent Back Passports and Bitcoin Histories.Sep 12FTX Creditors Got Up to 120% of Their Money Back. SBF Just Told the Supreme Court That's Why He's Innocent.Sep 11They Pointed AI Agents at Bitcoin's Encryption. Eight Weeks Later, Cracking It Got 86% Cheaper.
BTC -- --%
ETH -- --%
Fear & Greed F&G 71 Greed
ESC
Type to search articles
Someone Emailed Revolut From a Real Government Domain. Revolut Sent Back Passports and Bitcoin Histories.
BREAKING

Someone Emailed Revolut From a Real Government Domain. Revolut Sent Back Passports and Bitcoin Histories.

Revolut didn’t get hacked. It got asked.

On Saturday the 80-million-customer fintech confirmed that an “unauthorised third party” used an email address on a legitimate government agency’s domain to file fraudulent information requests, and that Revolut fulfilled them. What went out the door, per the notifications customers are now receiving:

  • Full name, date of birth, occupation
  • Home address, email, phone number
  • Copies of passports and driving licences
  • The facial-verification selfies paired with those documents
  • Account statements and IBANs
  • Withdrawal records
  • Full transaction histories, including every Bitcoin transaction

That is, roughly, the complete file a bank builds on you to satisfy Know Your Customer rules. It is also the complete file a kidnapper would want.

What Revolut is saying

The company’s statement, given to TechCrunch and The Block, calls it “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”

Revolut says a “limited” number of customers were affected, that its systems and customer funds were untouched, that it blocked the email address on discovery, and that it has notified the agency, law enforcement, data protection authorities and financial regulators. Affected users have been contacted directly.

What Revolut is not saying:

  • How many people were hit
  • Which country or market
  • Which government agency’s domain was used
  • Whether the attacker created a rogue mailbox inside the agency or took over a real official’s account
  • How many separate requests were fulfilled before anyone noticed

Revolut declined to name the agency. Former Mt. Gox CEO Mark Karpelès, who posted a copy of his own notification, made the obvious point: if the agency were named, every other bank and exchange could check their own logs for demands from the same mailbox. Right now they can’t.

Why “limited” is the scary word, not the reassuring one

Onchain investigator ZachXBT flagged the incident before most outlets had it, and his read was blunt: “While the incident is likely limited in size it seems to have been targeted at high net worth users.”

Think about what that means. A mass breach dumps a million rows into a Telegram channel and most of it is worthless. A targeted request against a short list of wealthy accounts, returning passports, selfies, home addresses and a ledger of exactly how much Bitcoin moved through each one, is a different product entirely. That is a shopping list.

Physical “wrench attacks” on known crypto holders have been climbing all year. The Ledger customer-data leak is still getting people robbed years later and just drew a $500 million class action. The difference here is that Ledger leaked names and addresses. Revolut leaked names, addresses, and proof of how much you’re worth.

The attack is old. The target is new.

Security people have a name for this: the fraudulent emergency data request. Attackers compromise or spoof a law-enforcement or government mailbox, send a request that looks like a legal demand, and count on the recipient’s legal team prioritising speed over verification. Apple, Meta, Discord and others have all been caught by versions of it.

What makes the Revolut case worse is that the email apparently wasn’t spoofed at all. Multiple reports say the request came from inside the agency’s actual domain infrastructure and carried valid authentication. SPF, DKIM and DMARC all did their job. The sender really was someone@agency.gov. Email security can’t save you when the email is genuine and the person isn’t.

That leaves process as the only defence: a callback to a known number at the agency, a check against a published contact list, a second approver, a mandatory delay. Revolut, by its own account, only discovered the fraud when it “later contacted the agency separately.” Which means the verification step existed. It just ran after the data was sent.

Terrible timing

Ten days ago Revolut got conditional approval from the OCC for a US national bank charter, with FDIC and Federal Reserve sign-off still pending and a target launch in the first half of 2027. It is also, by every report, weighing an IPO.

A bank that hands customer KYC files to whoever emails from a plausible-looking address is exactly the kind of operational-risk story that regulators put in the file. The GDPR exposure in Europe is separate and real: passport scans and biometric-adjacent selfies are special-category data, and “we were tricked” is not a defence the ICO or an EU DPA has historically found persuasive.

Why This Matters for Crypto Jobs

Every exchange, neobank and custodian in the world runs a law-enforcement response desk. Most of them are understaffed, most of them are measured on turnaround time, and most of them have never had an attacker send a request from a real government domain. As of this weekend, all of them are going to assume it can happen to them.

That produces demand in three places:

Law enforcement response and legal operations. The teams that receive, verify and fulfil government data requests just became a control function rather than a mailroom. Expect exchanges to add headcount, formal verification playbooks, callback procedures and audit trails. If you have compliance experience and can write a process that survives a genuine-but-fraudulent request, you are suddenly a hire.

Security engineering with a social-engineering focus. This breach was not a bug. It was a workflow. Companies want people who can threat-model processes, not just contracts and endpoints. Red-teaming the LE desk is going to be a line item.

Privacy and data minimisation. The uncomfortable question the industry keeps avoiding: why does a data request return the selfie and the passport and the full Bitcoin ledger in one bundle? Engineers who can build tiered disclosure, scoped access and just-in-time retrieval for KYC data are going to find a lot of open doors. The Ledger lawsuit and now Revolut make the business case for them.

For job seekers, one practical note. Revolut is one of the largest fintech employers in Europe with a big crypto footprint. Incidents like this don’t usually trigger layoffs. They trigger hiring in exactly the teams that failed.

What to do if you got the email

If Revolut notified you, assume the following are now in a criminal’s hands: your ID, your face, your address and a record of your crypto activity.

  • Treat any call, text or email that references your Revolut account or Bitcoin holdings as hostile by default, even if it quotes real details. That is the point of stealing real details.
  • Consider a fraud alert or credit freeze in your jurisdiction. Passport scans and DOB are enough to open accounts.
  • If you hold meaningful crypto in self-custody, this is the week to rethink whether your home address and your holdings should be connected in anyone’s database.
  • Ask Revolut, in writing, which agency’s domain was used. You have a legal right to know how your data was processed. The more people ask, the harder it is to keep quiet.

The Bottom Line

The system worked as designed. A government domain sent a request, the request passed authentication, a compliance process approved it, and the data went out. Nobody broke anything.

That’s the problem. The crypto industry spent three years building fortress-grade KYC databases because regulators demanded it. Those databases are now the most valuable target in the room, and the key to them is an email that looks official enough.


Building in crypto and want to work somewhere that takes this seriously? Compliance, security and privacy engineering roles are the most durable hiring in Web3 right now, and stories like this one are why. Find them at Cryptogrind, the job board for crypto and Web3 builders.

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs