Close Menu

    Stay Ahead with Exclusive Updates!

    Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!

    What's Hot

    Oracle’s Second Layoff Round of 2026 Cut 2,500 Jobs and Started with a 4am Slack Lockout

    September 19, 2026

    Revolut Was Tricked Into Handing Over Customer Passports by a Fake Government Request

    September 19, 2026

    Why NYC’s Sweeping Student AI Ban Is Destined to Fail

    September 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter)
    PhronewsPhronews
    • Home
    • Big Tech & Startups

      Oracle’s Second Layoff Round of 2026 Cut 2,500 Jobs and Started with a 4am Slack Lockout

      September 19, 2026

      Revolut Was Tricked Into Handing Over Customer Passports by a Fake Government Request

      September 19, 2026

      Why NYC’s Sweeping Student AI Ban Is Destined to Fail

      September 19, 2026

      DeepSeek Files for Shanghai IPO at Massive $74B Valuation

      September 17, 2026

      Claude Mythos 5 Refused to Stop Hacking Live Corporate Target

      September 17, 2026
    • Crypto

      A Firmware Flaw in One of the Most Trusted Bitcoin Hardware Wallets Just Drained Over $70 Million in Crypto. The Coldcard Breach Is a Reminder That Cold Storage Is Only as Safe as the Code Running Inside It

      August 29, 2026

      Market Collapse: What Happened to NFTs?

      April 23, 2026

      Quantum Computing Advances Force Coinbase and Institutional Custodians to Rethink Crypto Security

      March 8, 2026

      AI Assisted Hacking Groups Target Crypto Firms With Multi-Layered Social Engineering

      February 18, 2026

      Global Crypto Regulations Expand as 2026 Begins With New Data Collection Frameworks and National Laws

      January 16, 2026
    • Gadgets & Smart Tech
      Featured

      Tesla Cybercab Faces NHTSA Probe After Austin Launch

      By preciousSeptember 19, 2026
      Recent

      Tesla Cybercab Faces NHTSA Probe After Austin Launch

      September 19, 2026

      Chinese Humanoid Robots Just Ran 100 Metres Faster Than Usain Bolt. The Record Nobody Thought Would Fall to a Machine Just Did.

      September 5, 2026

      Meta Found a Zero-Click iPhone Vulnerability That Let Hackers Into Devices Without the Owner Doing Anything. Apple Patched It. The Fact That Meta Found It First Is the Uncomfortable Part.

      September 2, 2026
    • Cybersecurity & Online Safety

      Revolut Was Tricked Into Handing Over Customer Passports by a Fake Government Request

      September 19, 2026

      IDScan Hack Exposes 153 Million Driver’s Licenses on Dark Web

      September 17, 2026

      Hackers Chain PaperCut Zero-Days to Bypass Authentication

      September 17, 2026

      Claude Mythos 5 Refused to Stop Hacking Live Corporate Target

      September 17, 2026

      AI Agents Exploit PaperCut Zero-Day to Breach 395 Firms

      September 17, 2026
    PhronewsPhronews
    Home»Big Tech & Startups»Revolut Was Tricked Into Handing Over Customer Passports by a Fake Government Request
    Big Tech & Startups

    Revolut Was Tricked Into Handing Over Customer Passports by a Fake Government Request

    preciousBy preciousSeptember 19, 2026No Comments
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Photo Credit: Vuk Valcic/SOPA Images/LightRocket via Getty Images

    The process banks use to receive and respond to government requests for customer information have become the centre of a serious data breach at Revolut. 

    The British digital bank has confirmed that an unauthorised third-party used an email address from a legitimate government agency domain to send fraudulent information requests. Revolut treated the requests as genuine and disclosed sensitive customer records.

    About 680 customers were affected, according to people familiar with the investigation cited by the Financial Times, but Revolut has only described the number as “very limited.” 

    The exposed files reportedly included passports, driving licences, identity verification selfies, home addresses, phone numbers, bank account details and full transaction histories, including Bitcoin activity.

    A Genuine Address Carried a False Request

    The attackers did not need to break into Revolut’s banking systems, as they merely approached the company through an email channel that appeared to belong to a real government body with the authority to request customer information. And Revolut has not identified the agency. 

    However, the Financial Times reported that the hackers claimed they had compromised an Italian government email system and posed as law enforcement officers. And according to messages the alleged attackers sent to the newspaper, they exchanged emails with Revolut over several months and repeatedly requested records for selected customers. 

    The incident shows how a trusted communication channel can become part of an attack, especially as a legitimate domain can help an email pass routine technical checks but does not prove that the person behind the message is authorised to request private records.

    Passports, Selfies, and Financial Records Were Exposed

    Customer notifications shared publicly by blockchain investigator ZachXBT listed identity documents, verification photographs, account statements, IBANs, withdrawal records, and transaction histories among the exposed data. Names, occupations, dates of birth, and contact details were also reportedly included.

    Together, these records can create far greater risks than the exposure of one password or account number. Muhammad Yahya Patel, a cybersecurity adviser at Huntress, described the collection as a “complete identity theft kit” because it could help criminals impersonate victims, open fraudulent accounts, or build convincing scams. 

    Some victims may also face personal safety concerns. The Financial Times reported that the attackers selected people they believed held significant cryptocurrency assets. 

    Mark Karpelès, the former chief executive of collapsed crypto exchange Mt. Gox, said his home address was among the leaked information. “I have kids, we’re living together. My address is in those files,” he told The Guardian.

    Revolut Blocks the Address as Regulators Investigate

    Revolut said it blocked the email address after detecting the scam and alerted the government agency, law enforcement, data protection authorities, and financial regulators. The company has also contacted affected customers and said its systems and customer funds remain secure. 

    In addition, The UK Information Commissioner’s Office is assessing the incident after receiving a report from Revolut. 

    However, a group claiming responsibility later posted a $3 million ransom demand payable in Monero, although Revolut said it had received no direct demand from the group.

    For banks and technology companies, the breach exposes a difficult weakness in data request procedures. When official accounts can be compromised, checking the sender’s domain is only a minute part of verification. Requests for passports and detailed financial records also need independent confirmation through a separate, trusted channel before any information leaves the company.

    Revolut will have to build up a new, strong system after this case.

    cybersecurity Data Breach Digital banking Fintech Security KYC Data Revolut Social Engineering ZachXBT
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    precious
    • LinkedIn

    I’m Precious Amusat, Phronews’ Content Writer. I conduct in-depth research and write on the latest developments in the tech industry, including trends in big tech, startups, cybersecurity, artificial intelligence and their global impacts. When I’m off the clock, you’ll find me cheering on women’s footy, curled up with a romance novel, or binge-watching crime thrillers.

    Related Posts

    Oracle’s Second Layoff Round of 2026 Cut 2,500 Jobs and Started with a 4am Slack Lockout

    September 19, 2026

    Why NYC’s Sweeping Student AI Ban Is Destined to Fail

    September 19, 2026

    IDScan Hack Exposes 153 Million Driver’s Licenses on Dark Web

    September 17, 2026

    Comments are closed.

    Top Posts

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 2025
    Don't Miss
    Big Tech & Startups

    Oracle’s Second Layoff Round of 2026 Cut 2,500 Jobs and Started with a 4am Slack Lockout

    By preciousSeptember 19, 2026

    Oracle’s costly expansion into AI and cloud infrastructure is unfolding alongside another round of job…

    Revolut Was Tricked Into Handing Over Customer Passports by a Fake Government Request

    September 19, 2026

    Why NYC’s Sweeping Student AI Ban Is Destined to Fail

    September 19, 2026

    Tesla Cybercab Faces NHTSA Probe After Austin Launch

    September 19, 2026
    Stay In Touch
    • Facebook
    • Twitter
    About Us
    About Us

    Evolving from Phronesis News, Phronews brings deep insight and smart analysis to the world of technology. Stay informed, stay ahead, and navigate tech with wisdom.
    We're accepting new partnerships right now.

    Email Us: info@phronews.com

    Facebook X (Twitter) Pinterest YouTube
    Our Picks
    Most Popular

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025
    © 2025. Phronews.
    • Home
    • About Us
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.