Particle.news
Download on the App Store

Revolut Handed Passports and Bitcoin Histories to Fake Government Email

Control of a government mailbox let attackers pass standard email checks to obtain detailed KYC tied to on‑chain cryptocurrency records.

Overview

  • Revolut told a small group of customers on Sept. 11 that it had supplied sensitive files after fulfilling a request that appeared to come from a government agency email address.
  • The materials sent to the unauthorized recipient included full names, birth dates, home and email addresses, copies of passports or driver’s licenses, verification selfies, IBANs, account statements and complete transaction histories including Bitcoin records.
  • Revolut said the fraudulent messages carried valid domain authentication so staff treated them as genuine which suggests the attacker had access to or created a mailbox inside the real agency’s domain rather than merely spoofing the sender.
  • Threat actors have begun publishing some stolen files online and are making ransom demands, raising immediate extortion and targeted‑attack risks for affected customers.
  • Revolut says it blocked the sender, notified the implicated agency, law enforcement and regulators, and contacted impacted users while security experts question legal‑request verification controls and the wider risks of linking KYC to on‑chain data.