---
title: Fraudulent Government Requests Led Revolut to Disclose Passports and Bitcoin Records
description: Revolut says an unauthorised party used a real government agency's email domain to request customer data. A notice lists passports and Bitcoin records.
author: Darie Nani (Editor-in-Chief)
date: 2026-09-12T11:39:01.756Z
updated: 2026-09-12T11:40:33.409Z
canonical: https://www.sovereignmagazine.com/article/revolut-data-breach-fraudulent-government-request
image: https://cdn.nanimediahouse.com/revolut-featured.webp
categories: FinTech
content_type: News
region: United Kingdom
publication: Sovereign Magazine
about:
  - type: Organization
    name: Revolut
---

Revolut has confirmed that an unauthorised third party used a real government agency's email domain to submit fraudulent requests for customer information, and that it handed data over before establishing the requests were not genuine. The company has not said publicly what was disclosed. A notice circulated by an on-chain investigator, presented as the email Revolut sent to affected customers, lists passports, home addresses and full Bitcoin transaction histories.

The company gave its account to [BeInCrypto](https://beincrypto.com/revolut-data-breach-fake-government-request/), one of several outlets to report the still-developing story since the pseudonymous investigator ZachXBT circulated the notice on Telegram on Saturday morning. "Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," a spokesperson said, adding that "Revolut systems and customer funds are unaffected."

## A Real Government Domain Sent the Request

Under a heading "What happened?", the notice, which ZachXBT says reached customers on Friday 11 September, says: "Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency's email domain." It goes on: "As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request." That account matches the one Revolut gave BeInCrypto, though the company has not confirmed the document itself.

![Revolut customer notice listing the categories of data disclosed after a fraudulent government request](https://cdn.nanimediahouse.com/revolut-notice-zachxbt.webp)
*The customer notice circulated by ZachXBT, listing the categories of data Revolut disclosed. — Photo: Telegram/ZachXBT*

Domain authentication confirms that an email left a domain's own mail servers. It does not confirm who sent it, or whether they were entitled to ask. The sender here held an unauthorised account inside the agency's systems, so the check passed.

British police can ask a bank to hand over customer data without a court order, relying on the crime and taxation exemption in the Data Protection Act 2018, or on a threat to life. Compliance is voluntary, so the bank decides, and requests citing danger to someone are meant to be answered in hours.

## The Notice Lists Passports, Selfies and a Full Bitcoin History

According to the notice, the categories disclosed were full name, date of birth and occupation; home address, email address and telephone number; and a copy of the customer's passport or driving licence with the facial verification selfie taken during identity checks. Account statements went too, covering IBAN, account status, opening date and a Bitcoin wallet reference number, along with withdrawal records and the full transaction history, Bitcoin included.

Revolut told BeInCrypto that passcodes, login details and biometric data were not exposed and that no customer funds moved. The notice states that no biometric facial telemetry data was involved, though it lists [the verification selfie](https://www.sovereignmagazine.com/article/biometrics-in-action-the-reality-of-streamlining-customer-checks-for-uk-firms) itself among the documents disclosed.

## Revolut Has Not Named the Agency or Said How Many Customers Were Affected

Revolut has not identified the impersonated agency, citing the police investigation. It has not given a date for the fraudulent request, only that customers were emailed on Friday 11 September. It has not said how many people were affected, describing them as a limited number. It has not explained how someone came to hold an account inside a government email domain.

ZachXBT, who circulated the notice, writes that the request "seems to have been targeted at high net worth users" and was "likely limited in size". Revolut has not confirmed either point.

## Forged Emergency Data Requests Have Worked on Apple, Meta and Discord Before

The technique is not new. The security reporter Brian Krebs documented it in March 2022, when [hackers using compromised police email accounts](https://www.sovereignmagazine.com/article/young-english-speaking-hackers-reshape-global-cyber-threat-landscape) sent forged emergency data requests to Apple, Meta and Discord, citing an immediate threat to life. Discord acted on one within an hour.

The FBI warned in November 2024 that the pattern was turning towards finance, reporting a sharp rise in criminal forum sales of hacked police and government email credentials and naming banks and cryptocurrency platforms as targets. In March 2024 a forged request reached PayPal, supported by a fake mutual legal assistance document citing an invented child-trafficking investigation. PayPal refused it. So far as public reporting shows, the Revolut case is the first documented instance of a bank complying with one.

## Most of What the Notice Lists Cannot Be Changed

A date of birth, a passport, a home address and a record of when and how much Bitcoin someone moved stay accurate for years. Data of that kind has been linked to violent attacks on crypto holders before. A 2020 breach of Ledger's customer database exposed roughly 1.1 million email addresses and a further 272,000 records carrying names, phone numbers and home addresses, and victims later received letters demanding Bitcoin under threat of harm. In January 2025 Ledger co-founder David Balland and his wife were kidnapped from their home and freed by French police about 24 hours later. French investigators have logged 135 crypto-related physical attacks since 2023 and have tied part of that wave to leaked personal data.

## The ICO Leads Only If the Data Sat With Revolut's UK Bank

UK and EU data protection law both require a controller to notify its regulator within 72 hours of becoming aware of a breach, where feasible, and to tell affected individuals without undue delay where the risk to them is high. Revolut says it has blocked the sender, alerted the impersonated agency to the unauthorised mailbox on its domain, reported the matter to police and notified its data protection and financial regulators, without saying which.

Which regulator leads depends on where the disclosed data sat, and that is not public. [Revolut runs separate banking entities for the UK and the EU](https://www.sovereignmagazine.com/article/revolut-second-eu-banking-licence-france-dual-hub): the UK bank is supervised by the Information Commissioner's Office, while the EU business is licensed in Lithuania and answers to the Lithuanian data protection authority under the GDPR's one-stop-shop rule. The FCA does not supervise data protection, though its rules require Revolut to report a major operational or security incident without undue delay.

Penalties can reach £17.5 million or 4 percent of global turnover, though the final amounts are usually far lower: the ICO opened with £183.39 million against British Airways in 2019 and settled at £20 million.

## FAQ

**Q: Has Revolut been hacked?**
There is no suggestion that Revolut's systems were broken into. The company describes an external impersonation attack: someone using an unauthorised account inside a real government agency's email domain sent requests that passed Revolut's checks, and Revolut released customer data believing they were genuine. It says passcodes, login details and biometric data were not exposed and that no money moved. This is a separate matter from 2022, when a social engineering attack exposed data belonging to about 50,150 Revolut customers.

**Q: What is an emergency disclosure request?**
It is a request from a government or police body asking a company to hand over customer data quickly, without a court order, usually on the basis that someone is in danger. In the UK a bank can disclose voluntarily under the crime and taxation exemption in the Data Protection Act 2018, or where there is a threat to life. Because compliance is voluntary and speed is expected, the decision to release the data sits with the company rather than a court, and there is often little to verify beyond the address the request came from.

**Q: What to do if I receive a notice of data breach?**
Read it for the specific categories of data involved rather than assuming the worst or the least. Treat anything that cannot be changed, such as a passport number, date of birth or home address, as permanently exposed, and change what can be, starting with the email address and phone number on the account. Expect follow-up contact that quotes the leaked details back at you, since that is how criminals usually make use of a file like this, and treat any unexpected call or message that already knows your address or account history as suspicious rather than reassuring. If the company is UK-regulated you can raise the matter with the Information Commissioner's Office.
