Revolut Hands Over Customer Passports and Selfies After Accepting Fake Government Requests

Revolut delivered passports, selfies, and transaction histories to attackers who used forged government demands, then faced a 10,000 Bitcoin ransom note from the self-described perpetrators.

Revolut confirmed that it turned over customer data after receiving what turned out to be fabricated government requests. The exposed information included passports, selfies, and transaction histories. The company has notified affected customers and contacted the relevant government agency, law enforcement, and financial regulators.

Context

The incident marks a direct failure of Revolut’s verification procedures for official-looking demands. Before this event, the firm processed such requests under the assumption they originated from legitimate authorities. The attackers exploited that assumption to obtain material that can support identity fraud or further extortion.

Two separate reports describe the same sequence of events without contradiction. TechCrunch states that Revolut verified the breach occurred through fake government requests and that it has since alerted customers and regulators. The Register adds that the exposed records comprised passports, selfies, and transaction histories, and that the self-proclaimed culprits later demanded 10,000 Bitcoin. No further technical specifics on the forged documents or the exact verification steps that failed have been released by either source.

Details

The breach did not involve a network intrusion or stolen credentials in the conventional sense. Instead, the attackers presented documents that appeared to carry official authority, and Revolut’s internal process accepted them as genuine. Once the data left the company, the same actors contacted Revolut again, this time openly claiming responsibility and attaching a ransom demand denominated in Bitcoin. The company’s subsequent notifications to customers and to regulators followed standard incident-response steps, yet the initial acceptance of the forged requests remains the central operational failure.

Because the sources provide no additional numbers or timelines, the precise volume of records handed over and the duration of the exposure stay unknown. The only concrete elements available are the categories of data taken and the ransom figure stated by the perpetrators. Both reports treat these facts as established by Revolut’s own confirmation rather than independent verification.

Why it matters

Financial platforms hold identity documents that are difficult to replace once leaked. When those records reach attackers through simple impersonation rather than technical intrusion, the lapse points to process and training shortfalls rather than novel malware. Customers now face the practical task of monitoring for new accounts, loans, or travel documents opened in their names, while Revolut must demonstrate that its intake procedures for government correspondence have changed.

Regulators will likely examine whether existing rules on data-handling requests were followed and whether notification timelines met legal standards. The Bitcoin ransom demand shows the attackers view the data as monetizable leverage, not merely proof of access. Other fintech firms that rely on similar manual review steps for official requests now have a concrete case showing the cost of an incorrect approval.

Until Revolut publishes the precise checks that were bypassed, the incident remains an example of verification failure rather than an isolated social-engineering anecdote. The absence of contradictory claims between the two reports strengthens the core account: forged authority documents were accepted, customer records left the company, and a ransom followed. That sequence alone is enough to prompt every similar platform to re-examine how it authenticates demands that arrive with government letterhead.

---

Sources:

{
  "sources": [
    {
      "publisher": "TechCrunch",
      "title": "Revolut confirms customer data breach through fake government requests",
      "url": "https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/",
      "published_at": "2026-09-12T14:40:00.000Z",
      "summary": "Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators."
    },
    {
      "publisher": "The Register",
      "title": "Revolut falls for fake government requests, hands over customer data",
      "url": "https://www.theregister.com/cyber-crime/2026/09/14/revolut-falls-for-fake-government-requests-hands-over-customer-data/5296118",
      "published_at": "2026-09-14T11:26:00.000Z",
      "summary": "Passports, selfies, transaction histories exposed as self-proclaimed culprits demand 10,000 Bitcoin"
    }
  ],
  "word_count": 682
}

No comments yet