Revolut Handed Over Passports Because of One Email. So Who Sent It?
Revolut confirmed that a fake government email, sent from a real agency domain with genuine credentials, pulled customer files containing passports, selfies, and Bitcoin records. The breach wasn't technical. It was a convincing message and a human who believed it.
Who sent the email that got your passport? Right now, nobody outside Revolut knows. That's the part that should worry you.
Revolut confirmed to BeInCrypto that a fake government email actually worked. Someone used a real government agency's domain, carried genuine domain credentials, and asked for customer files. Revolut believed it was talking to the government. It sent the files.
A single email walked past the front door of a company with more than 50 million customers.
What Actually Walked Out the Door
The notices Revolut sent to affected customers describe the haul plainly. Passport scans. Selfies used for liveness checks. Bitcoin records.
That last one is the tell. Passports and selfies are standard KYC. Every exchange collects them. But Bitcoin records mean the file set tied a legal identity to on-chain activity. Whoever got that doesn't just have your face. they've your face and your bags.
The chain doesn't lie. If those records included wallet addresses or transaction history, anyone holding them can trace you forever. Addresses don't expire. Passports do.
Revolut is calling this a sophisticated attack. Look, here's the thing. It was an email.
Why This Hits Different
This isn't a database breach. Nobody exploited a smart contract or cracked encryption. Someone wrote a convincing message to a compliance desk and a human on the other end hit send.
That's the whole attack surface. And it's been the weak point for a decade.
Think about who wanted this exact combination of documents. A fake government email needs local knowledge. It needs to know which agency, which format, which tone gets a compliance team to move fast and skip a callback. That's not a script kiddie. That's someone who studied Revolut's process before they typed a word.
Could it be a nation-state? Maybe. Could it be a criminal crew building a KYC database to sell? Also possible. Revolut hasn't named a sender. BeInCrypto hasn't either. Until someone does, every affected customer is holding a passport number that's already burned.
What Security People Are Watching
According to incident responders I've talked to over the years, the first question in any social engineering case is always the same. Did the request go through an out-of-band check? A phone call to a known number. A second signer. A delay.
If the answer is no, that's the finding. Not the email.
Traders I've spoken with aren't reading this as a Revolut-only problem. They're reading it as a proof of concept. Every exchange, every neobank, every custody shop runs the same playbook. Government data requests come in. Compliance teams want to be cooperative. Speed gets rewarded.
This is bigger than people realize. One working template is now a shopping list for anyone who wants to phish the rest of the industry.
What to Watch Next
Three things. First, Revolut's regulatory disclosures. As a UK-regulated firm, it has reporting obligations, and the gap between when it noticed and when it notified customers will matter to the FCA.
Second, the sender. Watch for attribution from law enforcement or a claim of responsibility. If neither shows up in the next few weeks, assume the data is already listed on a forum.
Third, your own setup. If your passport and Bitcoin records were in that file set, change your wallet hygiene now. Fresh addresses for new positions. Long-term bags moved to cold storage you generated after the breach date, not before.
And keep asking the question Revolut hasn't answered. If a government email was enough, what else is?