|
Emjay24 (OP)
|
 |
September 12, 2026, 11:35:58 AM |
|
A fake government Email has led to serious data leak from Revolut, there was no breach, they gave it out thinking it was a request from the government. Seems some scammers got some targeted data by asking nicely this time around. A fake government email slipped through security controls at digital banking giant Revolut this week, exposing residential addresses, identity documents and bitcoin transaction histories belonging to a wide group of customers.
The request appeared to come from a legitimate government agency and carried credentials that passed Revolut’s checks. The company handed over customer information before separately contacting the agency and discovering that the request was fraudulent, according to notices sent to affected users.
The files reportedly included passports or driving licences, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs, account statements, withdrawal records and full transaction histories, including all bitcoin activity.
Revolut has yet to disclose how many customers were affected, and did not immediately respond to a CoinDesk request for comment on the matter.
It said in its email that customer funds remained safe and has since notified affected users and regulators and blocked the source of the request.
The weak point was authorization. Once the request cleared Revolut’s internal checks, someone posing as a government official gained access to the same deeply personal information the bank had collected to satisfy identity and compliance requirements.
https://www.coindesk.com/tech/2026/09/12/bitcoin-activity-passports-exposed-after-revolut-falls-for-fake-government-request
|
|
|
|
Upgrade00
Legendary

Activity: 2870
Merit: 2956
Community Manager - Brand Promotions ✅
|
 |
September 12, 2026, 11:48:40 AM |
|
Why is an actual government agency getting such easy access to private information that was entrusted to the service without the users being informed of it? Highly sensitive data like residential address and privacy documents should not be readily available on request. This circulation of private documents also creates multiple points of breaches. When you have a 3rd, 4th and 5th party involved, it has technically already been leaked.
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
|
|
|
|
Alpha Marine
|
 |
September 12, 2026, 12:11:39 PM |
|
It's shocking how easily these companies give out customers' private information to government agencies. They will always tell you, "your information will not be given to a third part" "your privacy is very important to us", but we all know these are not true. How can they simply give customers' details to anybody just because they asked? I thought the only way they could do that was by a court order. It's actually very scary if such a big company like Revolut, valued at over $100 billion, can easily give customers' data to a supposed government agency, so how much worse will it be for smaller companies? If they are not careful, there will be a lot of law suits coming their way because of this.
|
|
|
|
|
Emjay24 (OP)
|
 |
September 12, 2026, 12:34:57 PM |
|
Why is an actual government agency getting such easy access to private information that was entrusted to the service without the users being informed of it?
I think they can be given out without the consent of the individual if legal action is being initiated on the user and the court makes such a request from the service. My major concern is, why did they hand over the documents before contacting the agency to validate the claims contained in the email? That is the height of unprofessionalism and somehow it can be interpreted as an intentional act. I'm interested in what they have to say about this when they give an official statement on the matter. Now they've endangered the lives of their clients with this fatal error. Highly sensitive data like residential address and privacy documents should not be readily available on request. This circulation of private documents also creates multiple points of breaches. When you have a 3rd, 4th and 5th party involved, it has technically already been leaked.
Anybody who gives out his KYC should know that the data is subject to being leaked, when and how is what we don't know.
|
|
|
|
logfiles
Copper Member
Legendary

Activity: 2828
Merit: 2401
|
 |
September 12, 2026, 12:44:01 PM |
|
Revolut should be sued for the carelessness and they should be heavily fined. The breached their own privacy policy where I am pretty sure there is a line that says that "customer data is safe with them and won't be shared to third parties". In a normal world, the customers whose data was leaked should be compensated. Maybe that's when services like revolut will wake up and stop playing around with user data.
|
| | Sportsbet.io | │ |
| │ |
| │ | ████████████████████████ ██ ██████
██ ████████████████
MORE THAN A BET!
██ ████████████████
██ █████████████████████ ██ ████████ |
|
|
|
|
KiaKia
|
 |
September 12, 2026, 01:41:03 PM |
|
It's 2026, the year of data leak, I think this data leak thing isn't going to stop any time soon, this is a reckoning though, crypto uses should be careful who they give up their information to, if your data can lead back to your home don't use them online.
Bitcoin isn't even 500k yet and this is already happening, this is a big shame, after your email address and national ID do not give up sensitive information, the types that have your home number and address.
Remember that even AI will gladly take over data this days, they said data will be more costly than anything else in the future, maybe it's starting right in front of us now, this could be it.
|
|
|
|
|
noorman0
|
 |
September 12, 2026, 02:05:07 PM |
|
I read this news earlier today on ZachXBT's channel; given the data exposed, I would say the situation is critical for Revolut customers. It is as if no data privacy remains. Exposed data included: -Copy of passport and/or driver's license, plus the verification selfie -Account statements, IBAN, withdrawal records, and full transaction history including Bitcoin -Full name, date of birth, occupation -Home address, email, phone number This is a fiat financial service that has frequently experienced severe security incidents, ; throughout 2022 alone, there were 2 incidents involving data breaches and software exploits.
|
|
|
|
Upgrade00
Legendary

Activity: 2870
Merit: 2956
Community Manager - Brand Promotions ✅
|
 |
September 12, 2026, 02:20:24 PM |
|
I think they can be given out without the consent of the individual if legal action is being initiated on the user and the court makes such a request from the service. This does not look to be an inquiry into a user in particular but a blanket request for credentials of many of their users. The manner it was leaked also looks so casual, suggesting that this is a regular occurrence for them, handing out personal information on request. They have not commented or posted anything about this yet, which is concerning if the reports are true. We will have to wait for them to comment.
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
|
|
|
SquirrelJulietGarden
Legendary

Activity: 2114
Merit: 1003
|
 |
September 12, 2026, 02:30:50 PM |
|
A fake government Email has led to serious data leak from Revolut, there was no breach, they gave it out thinking it was a request from the government. Seems some scammers got some targeted data by asking nicely this time around.
Be phishing scammed by fake government emails is one of hardest ways to be scammed in my opinion. In each nation, you can easily check website domains from governments, and if they're actual government staffs, they will use emails with official domains from government sites. It's very easy to check and any fake, phishing emails can be identified quite easily too. Even if an email is legit, there will be next steps to check around government sites and even social media to confirm that what you received in email is official one or fake one. KYC basically is dangerous but KYC through different middle parties causes more danger. Why KYC is extremely dangerous – and useless.
|
|
|
|
|
Spaceman1000$
|
 |
September 12, 2026, 02:34:30 PM |
|
Scammers are relentless in their pursuit to get data that will link to people's crypto assets, wether is in the bank or personal wallet, There has been a lot of increasing cases going on, they are cloning emails and making it look very original, sometimes even when you do a double check it seemed like the original email from the government or from the authorities involved, and this is why they has been warnings ongoing about people being careful with their assets because this scammers are relentless in their effort in emptying people's asset. however in this case I feel the bank has a lot of blame, they should have an authority within the side of the government that they need to always authenticate information from, an email might looking like a request from the government to check details of customers but it lies on the bank to double check through their contacts to know if it's correct.
|
|
██ ██ ██████ | R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | ██████ ██ ██ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ██████████████ THE #1 SOLANA CASINO
██████████████ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ████████████▄ ▀▀██████▀▀███ ██▄▄▀▀▄▄█████ █████████████ █████████████ ███▀█████████ ▀▄▄██████████ █████████████ █████████████ █████████████ █████████████ █████████████ ████████████▀ | ████████████▄ ▀▀▀▀▀▀▀██████ █████████████ ▄████████████ ██▄██████████ ████▄████████ █████████████ █░▀▀█████████ ▀▀███████████ █████▄███████ ████▀▄▀██████ ▄▄▄▄▄▄▄██████ ████████████▀ | [ [ | 5,000+ GAMES INSTANT WITHDRAWALS | ][ ][ | HUGE REWARDS VIP PROGRAM | ] ] | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████████████████████████ PLAY NOW ████████████████████████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ |
|
|
|
Lucius
Legendary

Activity: 4088
Merit: 7781
A swap that needs a hand? zeto.cash@proton.me
|
 |
September 12, 2026, 02:57:23 PM |
|
Revolut should be sued for the carelessness and they should be heavily fined. The breached their own privacy policy where I am pretty sure there is a line that says that "customer data is safe with them and won't be shared to third parties". In a normal world, the customers whose data was leaked should be compensated. Maybe that's when services like revolut will wake up and stop playing around with user data.
They should, of course - but will that be the case? Many companies clearly take the storage and safeguarding of user data lightly—but what can you say when you aren't actually hacked, but rather politely asked, and you hand everything over to them on a silver platter? Many people will have big problems because of this, not only because of phishing messages and malicious calls, but also because of possible identity theft. But that is the risk of sending your personal documents to companies that obviously cannot distinguish a fake email from an official one, and then—without any further verification—hand everything over to the wrong people.
|
|
|
|
zabzob
Member

Online
Activity: 176
Merit: 71
|
 |
September 12, 2026, 03:01:32 PM |
|
Evidently it's a revolving door relationship between banks and governments. Gone are the days when banks stand up for their customers against intrusive governments. That all went out the window with the Patriot Act. Now the banks and the government eat at the same restaurant, and all it takes to get customer info is a quick phone call to a bank exec. No need to go through the courts. Stay safe, and never give your current home address to your bank.
|
|
|
|
|
SeriouslyGiveaway
Sr. Member
  

Activity: 840
Merit: 273
Bitz.io Best Bitcoin and Crypto Casino
|
 |
September 12, 2026, 03:22:56 PM |
|
They should, of course - but will that be the case? Many companies clearly take the storage and safeguarding of user data lightly—but what can you say when you aren't actually hacked, but rather politely asked, and you hand everything over to them on a silver platter?
One or two companies related to a data leak can be sued, lost the case, and have to pay money but people who lost their privacy will lost it forever. Data like personal documents after leaked will never be able to retrieved back and people in such situation will never gain their privacy back. What they can get is only some sort of money, if they are lucky enough to get it as compensation from companies. Suing a company to courts is never silver bullet to protect privacy (people actually lost it, knew about it before they sue a company) or improve their privacy.
|
|
|
|
joniboini
Legendary

Activity: 3038
Merit: 1926
|
 |
September 12, 2026, 05:50:45 PM |
|
How can they even share the data before verifying with the said agency is beyond me. I can understand if some average joe who has no exposure to spams and whatnot got tricked, but a big company with probably training and stuff like that over digital security? What's the procedure here? Sounds like it should be common sense to do a clarification with the party involved by sending an email or something similar before they start giving some sensitive data out. Makes me wonder how many attacks will deliberately use this tactic in the future since some companies are that sloppy when it comes to security.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|
Faisal2202
|
 |
September 12, 2026, 06:05:52 PM |
|
So this shows the procedure of data sharing between Revolut and the authorities is normal. So normal that they did not confirm it from anywhere else, they just sent the data required by the email just because the email belonged to an authority, which by the way was in the hands of scammers.
I wonder how they got their hands on this email?
I still can't comprehend how a platform can send that much data that easily over just an email request?
|
| MoBit | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | NO LOGS LOW FEES PGP GUARANTEE | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | | ▄██████▄▄▄ █████████████▄▄ ███████████████ ███████████████ ███████████████ ███████████████ ███░░█████████ ███▌▐█████████ █████████████ ███████████▀ ██████████▀ ████████▀ ░▀▀██▀▀ |
|
|
|
zabzob
Member

Online
Activity: 176
Merit: 71
|
 |
September 12, 2026, 06:08:34 PM |
|
How can they even share the data before verifying with the said agency is beyond me. I can understand if some average joe who has no exposure to spams and whatnot got tricked, but a big company with probably training and stuff like that over digital security? What's the procedure here? Sounds like it should be common sense to do a clarification with the party involved by sending an email or something similar before they start giving some sensitive data out. Makes me wonder how many attacks will deliberately use this tactic in the future since some companies are that sloppy when it comes to security.
Never underestimate the stupidity, incompetence and corruption of bank employees. Any information I share with a bank, I assume it's for sale on the darknet by the next day.
|
|
|
|
|
Cleanshit
Full Member
 

Activity: 336
Merit: 111
✿♥‿♥✿
|
 |
September 12, 2026, 06:20:28 PM |
|
So this shows the procedure of data sharing between Revolut and the authorities is normal. So normal that they did not confirm it from anywhere else, they just sent the data required by the email just because the email belonged to an authority, which by the way was in the hands of scammers.
I wonder how they got their hands on this email?
I still can't comprehend how a platform can send that much data that easily over just an email request?
How the scammers got the emails it not really the biggest problem here but it on how such sensitive information could be released base on a request without any form of another verification. They should be more than just a security checks before releasing data likes passports, transactions history and even him addresses. Just a mistake can just expose information that can’t be taken back or changed.
|
|
|
|
PX-Z
Legendary

Activity: 2296
Merit: 1393
♻️ Automatic Exchange
|
 |
September 12, 2026, 07:11:04 PM |
|
They just gave it away? Without any official letter from the office of the agency/government before giving such information and official request? Only from that email?. That's absolutely ridiculous from their end.
|
░░░░▄▄████████████▄ ░▄████████████████▀ ▄████████████████▀▄█▄ ▄███████▀▀░░▄███▀▄████▄ ▄██████▀░░░▄███▀░▀██████▄ ██████▀░░▄████▄░░░▀██████ ██████░░▀▀▀▀░▄▄▄▄░░██████ ██████▄░░░▀████▀░░▄██████ ▀██████▄░▄███▀░░░▄██████▀ ▀████▀▄████░░▄▄███████▀ ▀█▀▄████████████████▀ ▄████████████████▀░ ▀████████████▀▀░░░░ | | CCECASH | | | | |
|
|
|
PrivacyG
Legendary

Activity: 1638
Merit: 3067
Fight for Privacy.
|
 |
September 12, 2026, 07:52:30 PM |
|
How happy are the 'I have no thing to hide' customers right now about this? They may see me as a paranoid conspiracist. I am simply happy Revolut had no thing to expose from me! ----- Revolut should be sued for the carelessness and they should be heavily fined. The breached their own privacy policy where I am pretty sure there is a line that says that "customer data is safe with them and won't be shared to third parties". In a normal world, the customers whose data was leaked should be compensated. Maybe that's when services like revolut will wake up and stop playing around with user data.
Many of them would be hypocrites if they sued. They had no thing to hide when they shared selfies, identity and other documents, what do they have to hide now? Please note that I am not happy at all that they had their information leaked. I am simply saying they should stop 'having no thing to hide' and see why being a little bit paranoid is HEALTHY. Because this kind of thing happens more and more often and will be normalized as technology becomes integrated in daily life. Hell. My country had an old, annoying offline only system until a few years and now they are going full digital and I hate it. I will also have to do some of this because, of course, I can not be a ghost citizen. But. I am limiting my self to as FEW entities possible knowing who I am, having 'biometrical information' of me et cetera. This implicitly lowers the risk of being in the middle of a situation like this. And then you have people scanning their IRIS for some Shit Coins. What has the World become!
|
|
|
|
coinlary
Sr. Member
  

Activity: 770
Merit: 294
Make decisions without looking back
|
 |
September 12, 2026, 08:09:44 PM Last edit: September 13, 2026, 03:56:55 AM by coinlary |
|
It must have really been a nice request  . They need to expose the request itself for the public to see. I'm not sure how it's so convincing that they just hand it out right away without any further checks, or tThey are just a bunch of incompetent people running a centralised service. This is another reason to stay away from these services because they don't really value their customer data. All they really care about is money and more money.
|
|
|
|
|