Particle.news
Download on the App Store

Revolut Gave Sensitive KYC and Bitcoin Records After Fraudulent Government Email

The case shows a gap in email-based legal-request checks that can let attackers obtain verified KYC files, raising urgent privacy and regulatory risk.

Overview

  • Revolut disclosed copies of passports, verification selfies, contact details and full account statements including Bitcoin transaction histories after treating a request from a government agency email domain as legitimate.
  • On-chain investigator ZachXBT circulated the company notice that began reaching affected users on Friday, and Revolut says the number of impacted customers is very limited and those people have been contacted directly.
  • Technical checks that normally verify senders—SPF, DKIM and DMARC—passed for the fraudulent message, which reporting suggests came from an unauthorized mailbox inside a real agency domain rather than from a simple spoofed address.
  • Threat actors have started publishing some leaked identity documents and selfies and are publicly demanding ransom payments while threatening daily releases, making the incident an active extortion and privacy crisis.
  • Revolut says its systems and customer funds were not accessed, it blocked the sender and alerted the implicated agency, law enforcement and regulators, but the episode raises fresh questions about how firms verify legal requests and report data disclosures.