Back to blog
Hacks célèbresfintechfuite données

Revolut: Passports, KYC Selfies, and Bitcoin History Handed to an Attacker Impersonating a Government Agency

Published on 2026-09-146 min readCleanIssue

> TL;DR: Revolut, which claims more than 80 million customers across 160 countries (including 800,000 businesses), has notified a data breach to a subset of customers. An attacker impersonating a government agency requested personal data by email, using that agency's domain with valid domain authentication credentials — the request "was fulfilled under the reasonable belief that it was an authentic government agency request," per the company. The data handed over includes identity details (full name, date of birth, occupation), contact details, copies of identity documents (passport and/or driver's license), KYC facial verification selfies, account statements with IBANs, and full transaction history — including Bitcoin. The number of affected customers is undisclosed; investigator ZachXBT indicates targeting of high-net-worth users. Revolut says its systems and customer funds are unaffected.

The mechanism: institutional phishing that worked

The attack crosses no technical barrier: it exploits a business process. Fintech compliance teams routinely receive official requests (judicial inquiries, subpoenas, regulatory demands) by email. Here, the attacker used a real government domain with valid domain authentication credentials — the channel looked authentic in the technical sense, and the request was executed.

The result is a leak in the worst category: complete identity documents, facial verification biometrics, contact details, IBANs, and full transaction history. For high-net-worth targets — ZachXBT's thesis — this complete dossier is the ideal toolkit for identity theft, targeted banking fraud, and reconnaissance ahead of physical or digital attacks.

Revolut blocked the address on detection and alerted the relevant agency, law enforcement, data protection authorities, and financial regulators. This is the company's second major breach after September 2022 (50,150 customers).

Why this matters to you

If you run an HR, payroll, or finance SaaS, you hold the same role as Revolut: a custodian of massive personal data that answers official requests — and internal requests (HR, managers, support) that mimic the same channels. Three direct lessons:

  • Channel authentication is not authorization. A correctly signed email from a verifiable domain is still an email request. Official requests must go through verified dedicated channels (justice/police portals with mutual authentication, callback to registered contacts), never plain inbound email.
  • KYC data is a critical asset. Your identity document copies and verification selfies deserve bank-grade access controls: named access, logging, dual validation, encryption, expiry.
  • Selective targeting beats volume. A "limited" leak in count can be maximal in impact if it hits high-net-worth or high-responsibility profiles (executives, officials, law enforcement — as in Florida the same week).
  • What to do

  • Map your data disclosure processes: who can answer an external request, through which channel, with what verification of the requester's identity — and what happens when the requester is a convincing impostor.
  • Introduce dual human validation for any transmission of identity documents or sensitive data, with mandatory escalation to a designated owner.
  • Shrink the transmissible perimeter: the most legitimate official request never needs the full transaction history for an identity check. Send the minimum, not the whole file.
  • Log every disclosure (who, what, when, to which verified channel) so you can reconstruct a compromise window.
  • Train compliance and support teams on institutional phishing: they, not your developers, now hold the door to the data.
  • The broader lesson

    The two biggest leaks of the fortnight — Revolut and Florida's DAVID — were not opened by injection flaws or memory exploits, but by subverted trust channels (a convincing official-looking email, a stolen institutional account). The fastest-growing attack surface is not your code; it is your organization — the processes by which legitimate humans release data. Auditing them, through targeted social-engineering tests on disclosure workflows, is now as important as testing your endpoints.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit