Revolut Breach Shows How Fake Law Enforcement Requests Can Bypass Security Entirely
A hacker posing as an Italian law enforcement official convinced Revolut to hand over passport copies and sensitive personal data for 680 customers, then demanded a ransom of 10,000 Bitcoin. There was no hacking in the technical sense; the attacker simply exploited EU rules requiring companies to respond to official data requests, and Revolut appears to have believed the request was genuine.
The incident highlights a wider weakness in Know Your Customer (KYC) processes, which require businesses to collect and store large volumes of identity documents such as passports, selfies, and proof of address. This creates a valuable target for criminals, since a successful social engineering attempt can unlock a large trove of verified personal data at once. Analysts note this is part of a much bigger pattern: 343 million people in the United States alone were affected by data breaches in 2026.
The case also shows how regulatory compliance pressure can be turned against a company. Because businesses often fear penalties for refusing a law enforcement request, attackers can exploit that urgency to bypass normal verification checks entirely, using impersonation rather than technical exploits.