5x rewards · Early stage
Regulation

Revolut Tricked Into Leaking Customer Data via Fake Regulator Request

Ilustración: a dim corporate office with a bank of empty monitors. Ilustración generada con IA.
Ilustración generada con IA

Revolut disclosed sensitive customer data — including identity documents and Bitcoin transaction histories — after an unauthorized third party posing as a government agency tricked the fintech into complying with a fraudulent official-looking data request. The attacker operated from a compromised mailbox inside a real government agency’s email system, meaning the request passed standard authentication checks before anyone at Revolut realized it was fake.

Customers began receiving notifications on Friday, September 11, 2026, according to a report published the following day. Revolut has confirmed the request was fraudulent, blocked the sender, and started notifying both affected customers and regulators. The company has not named the government agency involved or disclosed how many users were affected, leaving significant gaps in the public understanding of the incident’s scope.

How a Fake Government Request Slipped Through

What makes this case notable is not that a company was fooled by a well-crafted phishing email — that happens constantly — but that the fraudulent request came from inside legitimate government infrastructure. The attacker didn’t need to spoof a domain or forge a convincing sender address; they used an actual mailbox within a real agency’s system, which meant the message cleared SPF, DKIM, and DMARC checks, the standard technical safeguards companies rely on to verify that an email genuinely originates from where it claims.

Those protocols exist to stop the most common form of email fraud: domain spoofing. They were never designed to catch a scenario where the attacker has already compromised a legitimate account inside a trusted institution. That distinction matters because it shows the failure point wasn’t Revolut’s spam filter or a careless employee clicking a bad link — it was a trust assumption baked into how financial institutions verify law enforcement and regulatory requests. If the sending domain is real and the technical authentication passes, most compliance teams have few tools left to question the legitimacy of the request itself.

Details about who was affected remain limited. Marc Zeller, founder of the Aave Chan Initiative, said he received a data disclosure notice from Revolut shortly after the company had separately threatened to close his account over missing verification data — an awkward juxtaposition that underscores how the same KYC machinery meant to protect customers can also become the vector through which their data leaks. Onchain investigator ZachXBT said the exposure appeared limited in scope and may have specifically targeted high-net-worth clients, a detail that, if accurate, suggests the attacker was not conducting a broad data grab but pursuing a more selective target list.

What This Means for Crypto Users and Fintechs

Revolut has said no funds, passwords, PINs, or private keys were reported stolen. That is a meaningful mitigating factor — this was not a hack of custodial infrastructure or a wallet compromise. But identity documents and Bitcoin transaction histories are themselves valuable and dangerous in the wrong hands. Passport scans and government IDs can be reused for account takeovers elsewhere or sold on. Transaction histories tied to real identities can expose wealthy individuals to targeted scams, extortion attempts, or physical security risks — a concern that has grown alongside the broader convergence of banking and crypto services, as seen in moves like Nubank’s expansion of stablecoin-powered global accounts beyond Latin America.

The incident also raises uncomfortable questions about the verification protocols fintechs use before releasing customer records to authorities. Compliance departments are built to respond quickly to legitimate law enforcement demands, often under legal deadlines that discourage lengthy independent verification. That urgency, paired with the difficulty of distinguishing a compromised-but-authentic government mailbox from a genuine one, creates a gap that this incident appears to have exploited.

Former Mt. Gox CEO Mark Karpelès, who has firsthand experience with the fallout of major data and security failures in crypto, noted that identifying the compromised agency could help other financial firms check whether they received similar fraudulent requests. His point highlights a broader industry weakness: without public disclosure of which agency’s system was breached, other institutions have no way to audit their own recent data-sharing history for the same red flags.

What to Watch Next

  • Whether Revolut or the undisclosed government agency eventually names the compromised mailbox or agency, allowing other financial firms to check their own records.
  • Any disclosure of the number of affected customers, which remains unpublished.
  • Regulatory response, given that Revolut has already notified authorities as part of its standard breach protocol.
  • Whether other fintechs or exchanges report similar fraudulent data requests, which would confirm this was part of a broader campaign rather than an isolated incident.

The episode arrives at a moment of heightened scrutiny over how crypto-linked financial data is handled across borders, a debate playing out in parallel through legislative efforts such as the Senate’s revised Clarity Act targeting fake DeFi activity ahead of an upcoming vote. As identity verification and blockchain transaction data increasingly sit inside the same compliance pipelines, incidents like this one are likely to sharpen calls for stronger authentication standards before sensitive records change hands — even when the request appears to come from a legitimate government source.

Source: CryptoSlate

This content is for informational purposes only and does not constitute financial or investment advice.

Informational and educational content; not financial, investment, legal or tax advice. Always do your own research.

Read. Comment. Earn.

Share a thoughtful take on this story. Quality comments are scored by AI and earn reward points.

Points (Proof Points) are internal and non-transferable, with no monetary value and no entitlement to $PROOF. Legal

Join the conversation