A sophisticated social engineering attack leveraging compromised law enforcement email infrastructure has resulted in a targeted Revolut data breach. British fintech giant Revolut confirmed it disclosed highly sensitive customer data to extortionists who submitted fraudulent Emergency Data Requests (EDRs) using an authentic government agency domain email address. The incident specifically targeted high-net-worth individuals and prominent figures in the cryptocurrency sector, exposing identity verification files and detailed financial transaction histories.
Upon detecting the unauthorized disclosure, Revolut blocked the compromised sender address and notified affected users, data protection regulators, financial oversight bodies, and law enforcement agencies. While Revolut stated that only a limited number of customers were impacted, the depth of data exposed places those individuals at severe risk of targeted financial theft and physical extortion.
How the Emergency Data Request Scam Works
Emergency Data Requests (EDRs) represent a critical vector where standard legal oversight is intentionally bypassed to save lives. Under international legal frameworks and corporate compliance policies, service providers and financial institutions can disclose non-public user data without a formal subpoena, court order, or search warrant if an official law enforcement agency asserts an immediate threat of death or serious physical injury.
Cybercriminals exploit this urgent operational workflow through compromised law enforcement accounts:
- Infrastructure Compromise: Threat actors gain control of legitimate government or law enforcement email accounts (
.govor national equivalents) via phishing, credential harvesting, or purchasing access from illicit marketplaces. - Forged Submissions: Attackers craft official-looking emergency requests alleging an imminent life-safety crisis, citing fake case numbers and urgent deadlines.
- Bypassing Authentication: Because the request originates from a valid government domain, automated email security controls (SPF, DKIM, and DMARC) validate the message as authentic.
- Data Disclosure: Compliance teams—under strict time pressure to avoid liability in alleged life-or-death situations—fulfill the request by exporting sensitive user dossiers directly to the attackers.
In Revolut’s case, extortion material circulated on Telegram indicates the attackers utilized a compromised Italian government domain (.it). Because the request arrived from a legitimate agency address, it bypassed initial verification protocols, leading compliance personnel to release complete customer files.
High-Value Victims and Exposed KYC Data
The perpetrators systematically targeted individuals with significant holdings in digital assets. Among those impacted are Marc Zeller, founder of the Aave Chan Initiative, and Mark Karpelès, former CEO of the Mt. Gox cryptocurrency exchange.
Zeller publicly revealed that the breach occurred shortly after Revolut required him to submit extensive compliance documentation under threat of account suspension within 20 days. The attackers appear to have leveraged this timing to siphon freshly updated Know Your Customer (KYC) packages.
Customer notifications sent by Revolut reveal an extensive list of exposed sensitive identity and financial records:
- Full names, dates of birth, residential addresses, and phone numbers
- Scans of government-issued passports and driver’s licenses
- Identity verification selfies and biometric compliance images
- Complete bank account statements and International Bank Account Numbers (IBAN)
- Detailed withdrawal and deposit records, including complete Bitcoin transaction logs
Exposing this level of KYC data creates immediate, severe risks for victims. Beyond conventional identity theft and SIM-swapping attacks, releasing precise physical addresses alongside cryptocurrency asset values exposes high-net-worth targets to targeted spear-phishing, extortion, home invasion, and physical coercion.
Threat Actor TTPs and Historical Pattern
Abusing EDR protocols is an established tactic previously popularized by cyber-extortion groups such as Lapsus$ and its successor threat groups between 2021 and 2022. During that campaign, threat actors repeatedly breached police department email accounts and government portals to issue fake EDRs against major tech firms, successfully pulling subscriber data from Apple, Meta, Discord, Snap, and Google.
The FBI previously issued alerts regarding this technique, warning of increased postings on criminal forums offering compromised law enforcement credentials specifically intended for fake EDR submissions. Once obtained, actors use the data for direct extortion against the service provider or secondary extortion aimed directly at the exposed high-net-worth victims.
Following the Revolut breach, the threat actors posted samples of stolen customer data on Telegram, demanding a ransom from Revolut to prevent a full leak. The Telegram account used to host the extortion proof has since been suspended.
Mitigating Fake Law Enforcement Requests
This breach underscores a systemic vulnerability in legal compliance workflows across tech companies and financial institutions: domain validation alone is insufficient when the underlying government email account is compromised.
Organizations handling sensitive customer records or financial data should implement strict verification controls for all incoming law enforcement and emergency requests:
- Mandatory Out-of-Band Verification (OOBV): Require compliance staff to independently verify all emergency requests before releasing data. Personnel must look up the official switchboard phone number for the requesting agency (never using contact numbers listed within the email itself) and verbally confirm the requesting officer’s identity and active case status.
- Strict Multi-Person Approval: Implement multi-party authorization protocols for EDR fulfillments involving high-risk account categories, high-net-worth profiles, or full KYC export packages.
- Transition to Authenticated Portals: Move away from accepting legal process via unauthenticated inbound email. Rely instead on secured, multi-factor-authenticated law enforcement portals (such as Kodex) that require verified agency credentials and audit logging.
- Cryptographic Signing for Requests: Urge legal and law enforcement liaisons to adopt digital signatures (such as PGP or S/MIME) tied to verified agency keys for urgent communications.
Related content
Global Crime Syndicates Leverage Generative AI to Scale High-Value Fraud
Security NewsUK ACRO Criminal Records Office Reprimanded After Unpatched CMS Led to Two-Year Breach
Security NewsAdobe Patches Maximum-Severity CVSS 10.0 Zero-Click Flaw in Campaign Classic
Security NewsCritical Adobe ColdFusion Vulnerability (CVE-2026-48282) Actively Exploited In The Wild
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call