Jon Tetreault

Writing · September 2026

The request came from the right address.

On a job site, the most expensive sentence you can hear is "the owner wants it changed." It usually arrives secondhand, in a hurry, from someone who sounds sure. The right response was never to argue. It was to call the owner, on the number you already had.

Someone told Revolut the government wanted customer files. Revolut didn't make the call.

On September 12, the fintech confirmed to TechCrunch that an unauthorized third party had used "a legitimate government agency domain email to submit fraudulent requests for information," and that Revolut had answered them. The company says its systems and customer funds were unaffected. It has not said how many people were hit, which agency's domain was used, or whether that mailbox was hacked or imitated.

What went out the door is about the worst list this industry can produce. According to The Register and The Block, the exposed records included names, dates of birth, home and email addresses, phone numbers, copies of passports and driver's licenses, verification selfies, account statements, withdrawal records and full transaction histories — bitcoin transactions included.

On-chain investigator ZachXBT, quoted by The Block, wrote that the incident "seems to have been targeted at high net worth users." The Register says people claiming responsibility are posting snippets of the data in Telegram groups and demanding 10,000 bitcoin. Nobody has confirmed they are who they say they are.

Nobody broke in

There is no exploit in this story. No bug, no drained contract, no stolen key. Someone sent a convincing request from a real return address, and a compliance process did exactly what it was built to do: comply.

That's the part that bothers me, because none of this is new. In November 2024 the FBI warned that criminals were using compromised US and foreign government email addresses to send fraudulent emergency data requests to companies. Those requests are built to be answered fast and without a court order, because in the real version someone's life is on the line. Revolut hasn't said what kind of request it received. But the pattern has carried a public FBI warning for almost two years.

A real return address proves where the letter was mailed from. It says nothing about who wrote it.

Why this list is different

Plenty of breaches leak an email and a password. You change the password and move on. This one ties together three things that should never share a row in a spreadsheet: who you are, where you sleep, and that you hold bitcoin.

That combination is what physical attackers shop for. CertiK's first-half 2026 report counted 52 verified wrench attacks — robberies and abductions aimed at crypto holders — up from 39 a year earlier. Home invasions went from 1 to 20. CertiK says attackers build their target profiles by combining leaked databases, compliance records, exchange customer data, social profiles and public wallet activity. Revolut's leak hands over several of those in one file.

There is also a detail specific to crypto. A bank statement goes stale. A blockchain doesn't. Revolut hasn't said what fields its withdrawal records held, but if any of them name an address you sent coins to, that address and everything that touches it stays public forever. You can't rotate a passport. You can't rotate a transaction history either.

The call Revolut didn't make

You can't fix Revolut's inbox. What you can do is refuse to repeat its mistake, because leaked customer data gets turned into targeted phishing by email and by phone, and the people holding this data now have a reason to try.

Here is what that looks like. A call or an email from "Revolut," or your bank, or a police officer. They know your date of birth. They might read back your address or a recent transaction. That knowledge is the entire trick. It feels like proof. It is the same proof Revolut accepted: the right details, from what looks like the right place.

So the rule is the carpenter's rule: never act on contact you didn't start. Hang up. Close the email. Find the number yourself — in the app you already installed, on the card in your wallet, on the agency's website you typed in by hand — and call back. A real bank will still be there when you do. A real officer can be reached through the front desk. Anyone who pressures you to stay on the line has just told you what they are.

If you are a Revolut customer and you received a notice, add two habits. Treat your home address as known. And stop mentioning what you hold anywhere it can be tied to your name. Neither costs a thing.

The owner's name on a note is not the owner. A government domain on an email is not the government. Verification means going around the message to the source, not reading the message more carefully.

Verify everything — especially the request that already knows who you are.

— Jon Tetreault, September 2026. The habits, tools, and checks behind this piece are what I teach in Crypto Security Mastery.