Revolut: Passports, KYC Selfies, and Bitcoin History Handed to an Attacker Impersonating a Government Agency
> TL;DR: Revolut, which claims more than 80 million customers across 160 countries (including 800,000 businesses), has notified a data breach to a subset of customers. An attacker impersonating a government agency requested personal data by email, using that agency's domain with valid domain authentication credentials — the request "was fulfilled under the reasonable belief that it was an authentic government agency request," per the company. The data handed over includes identity details (full name, date of birth, occupation), contact details, copies of identity documents (passport and/or driver's license), KYC facial verification selfies, account statements with IBANs, and full transaction history — including Bitcoin. The number of affected customers is undisclosed; investigator ZachXBT indicates targeting of high-net-worth users. Revolut says its systems and customer funds are unaffected.
The mechanism: institutional phishing that worked
The attack crosses no technical barrier: it exploits a business process. Fintech compliance teams routinely receive official requests (judicial inquiries, subpoenas, regulatory demands) by email. Here, the attacker used a real government domain with valid domain authentication credentials — the channel looked authentic in the technical sense, and the request was executed.
The result is a leak in the worst category: complete identity documents, facial verification biometrics, contact details, IBANs, and full transaction history. For high-net-worth targets — ZachXBT's thesis — this complete dossier is the ideal toolkit for identity theft, targeted banking fraud, and reconnaissance ahead of physical or digital attacks.
Revolut blocked the address on detection and alerted the relevant agency, law enforcement, data protection authorities, and financial regulators. This is the company's second major breach after September 2022 (50,150 customers).
Why this matters to you
If you run an HR, payroll, or finance SaaS, you hold the same role as Revolut: a custodian of massive personal data that answers official requests — and internal requests (HR, managers, support) that mimic the same channels. Three direct lessons:
What to do
The broader lesson
The two biggest leaks of the fortnight — Revolut and Florida's DAVID — were not opened by injection flaws or memory exploits, but by subverted trust channels (a convincing official-looking email, a stolen institutional account). The fastest-growing attack surface is not your code; it is your organization — the processes by which legitimate humans release data. Auditing them, through targeted social-engineering tests on disclosure workflows, is now as important as testing your endpoints.
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Florida DAVID Database: 200,000 Driver Records Claimed by ShinyHunters via a Police Account
Florida's DMV (FLHSMV) confirms a breach of the DAVID driver database discovered September 4, 2026. Official version: credentials of a Plant City Police Department user improperly stored on a personal device. ShinyHunters' version (200,000+ records claimed): a password reset flaw granting access to DMV and FBI accounts.
Liquid Network: 4,000 BTC Stolen via Elements Bug, 3,400 Returned After On-Chain Negotiation
On September 6, 2026, nearly 4,000 BTC (about $320 million, 95% of reserves) left the Liquid federation wallet via SideSwap's Peg-out Authorization Key, after L-BTC was created exploiting a bug in the Elements software. 3,400 BTC were returned the next day after signed on-chain exchanges; 598.5 BTC ($47M) remain held.
Brevo Hacked: Trezor Phishing Sent from help@trezor.io, 347,000 Emails Targeted
On September 9, 2026, an unauthorized actor accessed French email platform Brevo (formerly Sendinblue), compromising 120 customer accounts including Trezor's. Fake security alerts went out from the genuine help@trezor.io address to 347,000 subscribers; 2,500 people clicked the malicious link before the domain was taken down in 20 minutes.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.