{"id":298,"date":"2026-09-14T07:05:33","date_gmt":"2026-09-14T07:05:33","guid":{"rendered":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/"},"modified":"2026-09-14T07:05:33","modified_gmt":"2026-09-14T07:05:33","slug":"revolut-passport-bitcoin-fake-government-email-disclosure","status":"publish","type":"post","link":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/","title":{"rendered":"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email"},"content":{"rendered":"<p><em>Revolut confirmed on September 12, 2026 that it disclosed customer passports, verification selfies, and complete Bitcoin transaction histories to an unauthorized party after receiving a request from an email account hosted on a genuine government agency domain. The request passed SPF, DKIM, and DMARC authentication checks. Revolut describes the incident as &#8220;a sophisticated external impersonation scam&#8221; involving a &#8220;limited&#8221; number of customers, but has not published a victim count or named the agency whose infrastructure was used.<\/em><\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87_1 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">In this article<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6ab120a072f77\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"ez-toc-cssicon\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6ab120a072f77\"  aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#what-revolut-actually-sent\" >What Revolut Actually Sent<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#a-perfect-set-of-credentials-without-hacking-anything\" >A Perfect Set of Credentials Without Hacking Anything<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#this-attack-vector-has-been-public-since-2022\" >This Attack Vector Has Been Public Since 2022<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#the-records-that-cannot-be-changed\" >The Records That Cannot Be Changed<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#the-architectural-problem-is-collection-not-protection\" >The Architectural Problem Is Collection, Not Protection<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#trajectory\" >Trajectory<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"what-revolut-actually-sent\"><\/span>What Revolut Actually Sent<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><cite index=\"19-9,40-2\">The exposed data included birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver&#8217;s licenses<\/cite>, according to notifications reviewed by TechCrunch. <cite index=\"5-6,5-7\">The disclosed data also included verification selfies, IBANs, account statements, and Bitcoin wallet reference numbers<\/cite>. <cite index=\"5-8\">Full transaction histories, including Bitcoin transactions, were handed over<\/cite>.<\/p>\n<p><cite index=\"2-1\">The request originated from an account created within the authority&#8217;s own domain infrastructure and passed the checks commonly used to detect spoofed mail &#8211; SPF, DKIM and DMARC<\/cite>. <cite index=\"1-8\">The company handed over customer information before separately contacting the agency and discovering that the request was fraudulent<\/cite>. <cite index=\"2-2,2-3\">Only later, when the company contacted the agency to confirm the demand, did it learn that the mailbox was unauthorized. That outreach also alerted the government body to the rogue account on its own systems<\/cite>.<\/p>\n<p><cite index=\"23-5\">The company has not disclosed the agency involved, the exact number of affected customers or the period during which information was exposed<\/cite>. <cite index=\"19-7,22-11\">Blockchain investigator ZachXBT, who surfaced the customer notice, said the incident appeared to have been targeted at high net worth users<\/cite>. <cite index=\"22-2,22-8\">Former Mt. Gox CEO Mark Karpeles said he was among those affected<\/cite>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"a-perfect-set-of-credentials-without-hacking-anything\"><\/span>A Perfect Set of Credentials Without Hacking Anything<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><cite index=\"9-3,41-3\">The disclosure did not result from a compromise of Revolut&#8217;s core systems, mobile application, or customer accounts<\/cite>. <cite index=\"20-7,39-2\">The incident appears to have involved abuse of an authorized government email environment rather than a breach of Revolut itself<\/cite>. <cite index=\"6-7,6-8,6-9\">SPF, DKIM and DMARC were all reporting accurately. Those protocols answer one question, defined in RFC 7489: was this message sent by infrastructure the domain owner authorizes? When the attacker operates a real mailbox on that domain, the honest answer is yes<\/cite>.<\/p>\n<p><cite index=\"15-1,15-2\">Revolut&#8217;s compliance team had every technical reason to believe the request was genuine. So they processed it, handing over customer records to an unauthorized third party who had essentially forged a perfect set of credentials without ever touching Revolut&#8217;s internal systems<\/cite>. <cite index=\"15-3,15-4,15-5\">No passwords were stolen. No PINs or private keys were compromised. No customer funds were moved<\/cite>. <cite index=\"15-6\">But a trove of personal and financial data walked out the door through the front entrance<\/cite>.<\/p>\n<p>The mechanics are not mysterious. <cite index=\"20-4\">Like other regulated financial institutions, Revolut must respond to valid requests for customer information from law enforcement and government agencies<\/cite>. <cite index=\"24-7,24-8,24-9\">Financial institutions receive government data requests constantly. Law enforcement inquiries, court orders, regulatory demands. They are built to comply with these when properly verified<\/cite>. <cite index=\"24-10\">What happened at Revolut is a failure of that verification layer, not a technical breach in the conventional sense<\/cite>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"this-attack-vector-has-been-public-since-2022\"><\/span>This Attack Vector Has Been Public Since 2022<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><cite index=\"24-3,24-4\">As far back as 2022, security researcher Brian Krebs documented how attackers were spoofing emergency data requests to extract customer information from service providers<\/cite>. <cite index=\"6-2,6-5\">The FBI warned companies in November 2024 that credentials for police and government mailboxes were selling openly on criminal forums, after sellers began offering government mailboxes with coaching on how to use them<\/cite>.<\/p>\n<p><cite index=\"24-5,24-6\">The proposals to solve this, such as requiring digital signatures on government requests, have not been widely implemented. Even if they were, they would not fully address the problem of compromised accounts operating within legitimate government infrastructure<\/cite>. The problem is structural: email authentication protocols verify that a sender controls a mailbox on a domain, not that the sender is authorized by the organization that owns the domain. When an attacker compromises a government mailbox or creates one without authorization, every technical check passes.<\/p>\n<p>The regulatory framework governing how financial institutions respond to government requests assumes those requests are either legitimate or obviously fraudulent. <cite index=\"30-1,30-7\">FinCEN receives requests from federal law enforcement agencies and, after review, transmits those requests to designated contacts within financial institutions across the country once every two weeks<\/cite>. <cite index=\"36-10\">Financial institutions are required to provide customer financial records to government authorities only after receiving the proper written certification<\/cite>. That certification verifies the request is lawful, not that the person sending the email is who they claim to be.<\/p>\n<p><cite index=\"14-6,14-7\">Government-impersonation phishing has become a priority threat against regulated industries. The pretext exploits the one behavior security awareness training struggles to eliminate: deference to authority under time pressure<\/cite>. <cite index=\"14-8,14-9\">It targets the process rather than the password. Multi-factor authentication is irrelevant when the credential was never stolen; the attacker never needed a session cookie because the data arrived as an attachment<\/cite>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"the-records-that-cannot-be-changed\"><\/span>The Records That Cannot Be Changed<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><cite index=\"10-4,15-7,15-8\">The inclusion of cryptocurrency transaction records, including Bitcoin activity, is particularly sensitive because it could help criminals profile victims&#8217; wealth, trading behavior, wallet usage, and potential exposure to targeted scams. Cryptocurrency transaction data, combined with identity documents and verification selfies, gives bad actors a fairly complete toolkit for identity fraud, social engineering, or even targeted phishing campaigns against crypto holders<\/cite>.<\/p>\n<p><cite index=\"25-7\">The information handed over was exactly the kind a regulated fintech is obligated to collect and keep: passport or ID scans, biometric selfies used for liveness checks, and a record of on-chain activity tied to a named individual<\/cite>. <cite index=\"25-8,25-9\">Compliance data is a honeypot. To operate legally, platforms like Revolut collect and store the most identity-revealing documents a person owns, then link them to financial behavior<\/cite>. <cite index=\"25-12,25-13,25-14\">The value of a KYC archive to an attacker is not that it is hard to steal, but that once stolen it cannot be changed. You can reset a password. You cannot reset your face or your passport photo<\/cite>.<\/p>\n<p><cite index=\"5-16,5-17\">A password can be changed in a minute. A passport cannot<\/cite>. The exposed records now enable follow-on attacks that institutional security controls cannot prevent. <cite index=\"5-15\">The exposed records contain exactly the details attackers would use to impersonate customer service, initiate account recovery workflows, or construct convincing pretexts for further fraud<\/cite>.<\/p>\n<p>Revolut has not disclosed whether the attack was opportunistic or targeted, but the scope of the data and the choice of victims suggests intention. <cite index=\"18-8,18-9,18-10\">Revolut has published no victim count, no date range for the requests, and no name for the agency whose domain was used. Without a count, nobody can tell whether &#8220;limited&#8221; means nine people or nine hundred. Without the agency name, every other firm that answers requests from that same domain is still exposed and does not know it<\/cite>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"the-architectural-problem-is-collection-not-protection\"><\/span>The Architectural Problem Is Collection, Not Protection<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The lesson here is not that Revolut failed to protect customer data. The lesson is that the data existed in a concentrated, linked, and legally mandated form that made it a single point of failure. The same regulatory requirements that force financial institutions to collect and retain identity documents, biometric images, and transaction histories also make those institutions honeypots for attackers who understand how to manipulate the legal request process.<\/p>\n<p>A technical breach requires an intrusion detection response. A successful government impersonation attack requires rethinking what data regulated entities are required to hold and how long they must keep it. The problem is not the email authentication protocol; the problem is that KYC requirements centralize the most sensitive identity and financial data in systems designed to answer government requests quickly. Every institution that holds this data and answers these requests is exposed to the same vector.<\/p>\n<p>Verification does not require permanent retention. Decentralized verification schemes, zero-knowledge proofs, and selective disclosure protocols can satisfy regulatory requirements without creating a permanent dossier that links a face, a passport number, a home address, and a transaction history. None of these are hypothetical. They are operational and used by services that prioritize architecture over compliance theater.<\/p>\n<p>Email verification does not require biometric selfies or government-issued ID scans. For users who require verifiable claims without centralized identity storage, protocols like PQCServer enable cryptographic proofs that satisfy third-party requirements without transmitting or storing the underlying documents. The architecture assumes that the entity verifying identity and the entity operating the service are not the same, and that documents should never enter a system designed to answer government requests.<\/p>\n<p>The Revolut incident does not demonstrate sophisticated attackers exploiting a zero-day vulnerability. It demonstrates attackers exploiting the expected behavior of a compliance process that was designed assuming government requests are always legitimate or always detectable as fraudulent. That assumption no longer holds.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"trajectory\"><\/span>Trajectory<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The market for compromised government mailboxes will expand, not contract. The FBI warning in November 2024 was not predictive, it was descriptive. The infrastructure for this attack already exists, is actively traded, and has now been demonstrated against a regulated financial institution with 80 million customers and a pending US banking license. Every other financial institution that relies on email domain authentication to verify government requests is exposed to the same vector. The problem is not solvable by adding another verification step; the problem is that the verification process assumes that control of a mailbox implies authorization by the organization, and attackers now routinely violate that assumption. The structural fix is to reduce what is collected, limit how long it is kept, and separate verification from storage. Until that happens, every centralized KYC archive remains a target, and every government email domain remains a potential vector.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Revolut handed customer identity documents and complete Bitcoin transaction histories to an attacker operating from within a legitimate government agency email domain, exposing a structural weakness in how financial institutions verify law-enforcement data requests.<\/p>\n","protected":false},"author":1,"featured_media":297,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[523,528,529,248,166,527,522,525,521,526,524,530],"class_list":["post-298","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tor-anonymity","tag-bitcoin-transaction-history","tag-compliance-architecture","tag-data-minimization","tag-email-authentication","tag-government-impersonation","tag-identity-documents","tag-kyc-data","tag-law-enforcement-requests","tag-revolut","tag-social-engineering","tag-spf-dkim-dmarc","tag-zachxbt"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email - Onion Mail \u2014 Privacy, Encryption &amp; Tor<\/title>\n<meta name=\"description\" content=\"Revolut disclosed passports, verification selfies, and Bitcoin transaction histories after a fraudulent request from a real government domain passed all technical checks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email - Onion Mail \u2014 Privacy, Encryption &amp; Tor\" \/>\n<meta property=\"og:description\" content=\"Revolut disclosed passports, verification selfies, and Bitcoin transaction histories after a fraudulent request from a real government domain passed all technical checks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/\" \/>\n<meta property=\"og:site_name\" content=\"Onion Mail \u2014 Privacy, Encryption &amp; Tor\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-14T07:05:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/onionmail.org\/wp-content\/uploads\/2026\/09\/government-20260914.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Onion Mail\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Onion Mail\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/\"},\"author\":{\"name\":\"Onion Mail\",\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/#\\\/schema\\\/person\\\/165910c3149db6a9320ddae7d7a17cab\"},\"headline\":\"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email\",\"datePublished\":\"2026-09-14T07:05:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/\"},\"wordCount\":1562,\"image\":{\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/onionmail.org\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/government-20260914.jpg\",\"keywords\":[\"Bitcoin transaction history\",\"compliance architecture\",\"data minimization\",\"email authentication\",\"Government Impersonation\",\"identity documents\",\"KYC data\",\"law enforcement requests\",\"Revolut\",\"social engineering\",\"SPF DKIM DMARC\",\"ZachXBT\"],\"articleSection\":[\"Tor &amp; Anonymity\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/\",\"url\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/\",\"name\":\"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email - Onion Mail \u2014 Privacy, Encryption &amp; Tor\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/onionmail.org\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/government-20260914.jpg\",\"datePublished\":\"2026-09-14T07:05:33+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/#\\\/schema\\\/person\\\/165910c3149db6a9320ddae7d7a17cab\"},\"description\":\"Revolut disclosed passports, verification selfies, and Bitcoin transaction histories after a fraudulent request from a real government domain passed all technical checks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/#primaryimage\",\"url\":\"https:\\\/\\\/onionmail.org\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/government-20260914.jpg\",\"contentUrl\":\"https:\\\/\\\/onionmail.org\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/government-20260914.jpg\",\"width\":1200,\"height\":800,\"caption\":\"government - red padlock on black computer keyboard\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/revolut-passport-bitcoin-fake-government-email-disclosure\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/\",\"name\":\"Onion Mail \u2014 Privacy, Encryption & Tor\",\"description\":\"Anonymous email, PGP encryption and post-quantum security guides\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/#\\\/schema\\\/person\\\/165910c3149db6a9320ddae7d7a17cab\",\"name\":\"Onion Mail\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f7d6948c15418aed2d5fc684c551bb93fe70d354338e034960230227dad93ec9?s=96&d=initials&r=g&initials=in\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f7d6948c15418aed2d5fc684c551bb93fe70d354338e034960230227dad93ec9?s=96&d=initials&r=g&initials=in\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f7d6948c15418aed2d5fc684c551bb93fe70d354338e034960230227dad93ec9?s=96&d=initials&r=g&initials=in\",\"caption\":\"Onion Mail\"},\"sameAs\":[\"https:\\\/\\\/onionmail.org\"],\"url\":\"https:\\\/\\\/onionmail.org\\\/blog\\\/author\\\/adminblogonion\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email - Onion Mail \u2014 Privacy, Encryption &amp; Tor","description":"Revolut disclosed passports, verification selfies, and Bitcoin transaction histories after a fraudulent request from a real government domain passed all technical checks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/","og_locale":"en_US","og_type":"article","og_title":"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email - Onion Mail \u2014 Privacy, Encryption &amp; Tor","og_description":"Revolut disclosed passports, verification selfies, and Bitcoin transaction histories after a fraudulent request from a real government domain passed all technical checks.","og_url":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/","og_site_name":"Onion Mail \u2014 Privacy, Encryption &amp; Tor","article_published_time":"2026-09-14T07:05:33+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/onionmail.org\/wp-content\/uploads\/2026\/09\/government-20260914.jpg","type":"image\/jpeg"}],"author":"Onion Mail","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Onion Mail","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#article","isPartOf":{"@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/"},"author":{"name":"Onion Mail","@id":"https:\/\/onionmail.org\/blog\/#\/schema\/person\/165910c3149db6a9320ddae7d7a17cab"},"headline":"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email","datePublished":"2026-09-14T07:05:33+00:00","mainEntityOfPage":{"@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/"},"wordCount":1562,"image":{"@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#primaryimage"},"thumbnailUrl":"https:\/\/onionmail.org\/wp-content\/uploads\/2026\/09\/government-20260914.jpg","keywords":["Bitcoin transaction history","compliance architecture","data minimization","email authentication","Government Impersonation","identity documents","KYC data","law enforcement requests","Revolut","social engineering","SPF DKIM DMARC","ZachXBT"],"articleSection":["Tor &amp; Anonymity"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/","url":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/","name":"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email - Onion Mail \u2014 Privacy, Encryption &amp; Tor","isPartOf":{"@id":"https:\/\/onionmail.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#primaryimage"},"image":{"@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#primaryimage"},"thumbnailUrl":"https:\/\/onionmail.org\/wp-content\/uploads\/2026\/09\/government-20260914.jpg","datePublished":"2026-09-14T07:05:33+00:00","author":{"@id":"https:\/\/onionmail.org\/blog\/#\/schema\/person\/165910c3149db6a9320ddae7d7a17cab"},"description":"Revolut disclosed passports, verification selfies, and Bitcoin transaction histories after a fraudulent request from a real government domain passed all technical checks.","breadcrumb":{"@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#primaryimage","url":"https:\/\/onionmail.org\/wp-content\/uploads\/2026\/09\/government-20260914.jpg","contentUrl":"https:\/\/onionmail.org\/wp-content\/uploads\/2026\/09\/government-20260914.jpg","width":1200,"height":800,"caption":"government - red padlock on black computer keyboard"},{"@type":"BreadcrumbList","@id":"https:\/\/onionmail.org\/blog\/revolut-passport-bitcoin-fake-government-email-disclosure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/onionmail.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email"}]},{"@type":"WebSite","@id":"https:\/\/onionmail.org\/blog\/#website","url":"https:\/\/onionmail.org\/blog\/","name":"Onion Mail \u2014 Privacy, Encryption & Tor","description":"Anonymous email, PGP encryption and post-quantum security guides","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/onionmail.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/onionmail.org\/blog\/#\/schema\/person\/165910c3149db6a9320ddae7d7a17cab","name":"Onion Mail","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f7d6948c15418aed2d5fc684c551bb93fe70d354338e034960230227dad93ec9?s=96&d=initials&r=g&initials=in","url":"https:\/\/secure.gravatar.com\/avatar\/f7d6948c15418aed2d5fc684c551bb93fe70d354338e034960230227dad93ec9?s=96&d=initials&r=g&initials=in","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f7d6948c15418aed2d5fc684c551bb93fe70d354338e034960230227dad93ec9?s=96&d=initials&r=g&initials=in","caption":"Onion Mail"},"sameAs":["https:\/\/onionmail.org"],"url":"https:\/\/onionmail.org\/blog\/author\/adminblogonion\/"}]}},"_links":{"self":[{"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/posts\/298","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/comments?post=298"}],"version-history":[{"count":0,"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/posts\/298\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/media\/297"}],"wp:attachment":[{"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/media?parent=298"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/categories?post=298"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/onionmail.org\/blog\/wp-json\/wp\/v2\/tags?post=298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}