Sponsored by

How 2M+ Professionals Stay Ahead on AI

AI is moving fast and most people are falling behind. 

The Rundown AI keeps you ahead of the curve. 

It's a free AI newsletter that keeps you up-to-date on the latest AI news, and teaches you how to apply it in just 5 minutes a day.

Plus, complete the quiz after signing up and they’ll recommend the best AI tools, guides, and courses — tailored to your needs.

THE DEAD DROP // ISSUE NO. 118 // 09.15.2026 EYES ONLY
 
The Dead Drop
FRAUD · POWER · PSYOPS
 
A forged government email asked Revolut for its richest customers, and Revolut answered.

At 9:59PM on the night of September 11, an email landed in the inboxes of some of Revolut's wealthiest customers. It came from Revolut, it was genuine, and it carried the worst kind of news a bank can deliver. Your data is gone, it said, and we are the ones who gave it away.

Days earlier, someone had emailed Revolut from an address on a real government agency's domain and asked for customer information. The message looked like the kind of official demand a bank fields all the time. It passed every automated check an email can pass. Revolut read it as a legitimate government request and handed over the files.

The files were not thin. For each targeted customer they held the full name, date of birth, occupation, home address, phone number, a scan of a passport or driver's license, the selfie taken to verify that passport, account statements, IBANs, withdrawal records, and the complete Bitcoin transaction history attached to that person's name. Revolut has called the number of victims limited. It has not said how limited, and it has not named the agency whose identity was borrowed to pull this off.

What the company will confirm is the shape of it. Nobody broke a password. Nobody cracked a vault. The bank was asked, in what looked like an official voice, and it said yes.

GM, WELCOME BACK TO THE DEAD DROP.

The Email That Passed Every Test

Email carries three standard defenses that check whether a message really came from the domain it claims: SPF, DKIM, and DMARC. You do not need to know how they work. You need to know what they prove, which is only that the email truly came from that domain, not that the person who sent it had any right to send it. The attacker was not spoofing a government address from the outside. The attacker was sending from inside a real government mailbox, or one close enough, so all three checks came back green. The technology did its job perfectly and told Revolut a lie.

From there it was a judgment call, and the judgment failed. Banks receive government and law enforcement demands constantly, and there is heavy pressure to answer them quickly, especially when a request claims urgency. Revolut treated the message as a real legal request and released the dossier. In its own words:

"A sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."

The crypto investigator known as ZachXBT, who tracks this kind of theft for a living, looked at who got hit and concluded the operation was aimed at high net worth users. That is not an accident of the data. That is a shopping list. Among the names surfacing in the leaks were the tennis player Alexander Shevchenko and Felix Roemer, chief executive of the gaming firms Gamdom and Skinscom.

Note what was NOT taken, because it tells you the intent. The attackers did not get passwords, card PINs, account balances, or the private keys to anyone's crypto. They did not want to drain an account and trip an alarm. They wanted the identity behind the account: the passport, the face, the address, and the transaction history that says exactly how much this person is worth and where they keep it. This was reconnaissance, dressed up as the government.

The Power of Subpoena

Move from London to your own country, because this is not a Revolut problem and it is not a European one. It is the design of the system you already live inside.

In the United States, a company that holds your data generally cannot give it to the government without legal process. A prosecutor or a grand jury issues a subpoena. A judge signs a court order or a warrant after someone shows cause. Each of those leaves a record and passes in front of a person whose job is to say no. That is the front door, and it is guarded.

There is also a side door. A federal law, 18 U.S.C. 2702(b)(8), lets a company voluntarily hand over your data with no subpoena, no warrant, and no judge, as long as it believes in good faith that someone faces a danger of death or serious physical injury. The exception exists for real emergencies, a kidnapping in progress or a caller threatening suicide, the cases where waiting for a judge could get someone killed. A request through that door is called an emergency data request, an EDR, and it needs no seal, no signature, and no court. It needs an email and a story.

The volume is the reason nobody has time to check. Verizon alone reported more than 36,000 emergency requests in a single six-month period and complied with roughly 90% of them. Across the industry, emergency requests run between 5 and 30% of all law enforcement demands. The people answering them are triaging a flood.

Criminals worked out years ago that the side door has no lock. In 2021, a crew of mostly teenagers operating as Lapsus$ used compromised police email accounts to send forged emergency requests to Apple, Meta, and Discord, and the companies handed over user data. When Bloomberg and the reporter Brian Krebs exposed the wave in March of 2022, Krebs described what the criminals had really acquired. They had gained, he wrote, "the power of subpoena." It did not stay a data problem. In October of 2023, a man sent Verizon a fake emergency request from a ProtonMail address, received a woman's home address and call logs, and showed up at her house armed. By November of 2024 the FBI issued a public advisory warning that criminals were selling stolen government email credentials on crime forums, with sellers claiming access to police accounts in more than two dozen countries.

The market matured the way every criminal market does. Today a working fake emergency request runs $1,000 to $3,000 through people who will send it for you, an instruction kit sells for about $100, and a verified police email account goes for around $1,000, with some sellers advertising turnaround under an hour. This is where careful habits stop mattering, and I mean that as a warning, not an insult. You can use a different password everywhere, freeze your credit, and refuse every phishing email for the rest of your life, and none of it touches this. Somewhere out there is a magistrate's email login for a county you have never visited, one of roughly 18,000 law enforcement jurisdictions in this country, and the company holding your data has no real way to know whether a request from that account is a judge in South Texas or a teenager in another hemisphere who bought the password for a thousand dollars. Your bank answers to a badge it cannot inspect.

◆ THE OPERATIVE'S OBSERVATION

Think about who holds a copy of you right now. Your bank and your brokerage. Your doctor, and the billing company behind your doctor. Your lawyer. Your phone carrier. The church directory. The kid's school. A friend who saved a photo of your passport in a text thread to book a trip. Every one of them is a door into your life, and you do not control the lock on any of them.

Your privacy is capped by the least careful institution that holds your data.

You can run your own security like a professional and still be undone by a receptionist who clicked a link or a records clerk who answered an official-looking email on a busy afternoon. Revolut is not a story about one bank's mistake. It is a story about the dozens of custodians who hold your data and answer to requests you will never see, and about the fact that no one sends you a copy when they give you away.

The Second Wave

The theft was the first fraud. The second one started the moment the news broke, and it will take more money from more people than the breach itself.

Within a day of the leak, the thieves began posting customer files on X and Telegram, with a message aimed squarely at the company:

"We're gonna start releasing more and more data everyday until Revolut pays for leaking their customers."

That is extortion pointed at Revolut, and the customers are the leverage. Their names, faces, and balances are the currency being spent.

Then come the saviors. After every large breach, a second layer of criminals arrives wearing the mask of help. They email the victims. They buy search ads. They stand up websites carrying the real company's logo, colors, and login box, sometimes a near-perfect clone of the Revolut site, and they promise to secure your account, reverse the fraud, or recover funds you have not even lost yet. A frightened person who just learned that their passport and crypto history are sitting on Telegram is exactly the person who clicks. The recovery scam is one of the oldest plays in the business, and a fresh breach is its harvest season.

What makes this one crueler is the channel. Revolut is doing the responsible thing and notifying victims directly, by email, telling them what happened and warning them to watch for phishing. The scammers are sending email that looks the same, from addresses that look close enough, about the same breach, offering the same help. The true notice and the fake notice arrive in one inbox, on one day, about one event, and both tell you to act now. Revolut cannot fix that, because it does not own your inbox, and the criminals understand something the rest of us would rather not: the single moment you are most willing to believe an email from your bank is the moment your bank actually needs to email you.

Field Manual

The first four are for anyone whose data sits with a company that could be fooled, which is everyone. The last two are for the exposed, and for the people who answer these requests for a living.

01 Treat every breach email as hostile until you verify it yourself. Do not click a link or call a number inside any message about a breach, including the genuine one from your own bank. Open the app you already have, type the address by hand, or call the number printed on the back of your card. The real notice and the fake notice look alike, so stop trying to tell them apart and verify through a channel you opened.
02 No legitimate service emails you first to recover your money. There is no company that watches the news, sees that you were breached, and reaches out to reverse it for a fee. Anyone who contacts you offering fund recovery is running the second fraud. Report it to the FBI at ic3.gov and delete it. Paying a recovery fee is how a victim loses the money twice.
03 Assume the dossier is permanent and act on that. Passport numbers, birth dates, and a Bitcoin transaction history do not expire. If your crypto identity was exposed, move funds to wallets and addresses that were never linked to the leaked accounts, because a blockchain address tied to your name stays tied to it. Freeze your credit at all six bureaus, Equifax, Experian, TransUnion, Innovis, ChexSystems, and NCTUE, so the identity file cannot be used to open new accounts.
04 If your balances and your address leaked together, treat it as physical security. Criminals use leaked wealth data to pick targets for extortion and home invasion, a tactic the crypto world calls a wrench attack, because the weakest link is not the password, it is a person willing to threaten you in your driveway. Do not confirm your holdings to anyone, vary your routines, and look at what a stranger can find about your home address online.
05 Ask your custodians a question they probably cannot answer. How do you verify a government or law enforcement request before you hand over my data, and will you tell me if you do. Your bank, your broker, your doctor, your phone carrier, and your lawyer all hold pieces of you and all field official-looking requests. Give each of them only what the relationship requires, and close accounts you no longer use, because data that is not held cannot be handed over.
06 If you answer legal requests for a living, stop trusting the domain and verify the human. SPF, DKIM, and DMARC confirm the mailbox, not the authority behind it, and a compromised real account passes all three. Verify the agency against an independent registry, confirm the named investigator actually works there, call back on a published agency number rather than one supplied in the email, and log every request so a pattern of abuse becomes visible. The emergency exception was written for kidnappings, not for a queue you clear on autopilot.
◆ THE FRAUDFATHER BOTTOM LINE

Every institution that holds your data has a government-request door, and that door is guarded by an email inbox and a tired person under pressure to say yes. Revolut passed every technical check and failed the only one that mattered, which was whether the request was real. The attackers did not have to be sophisticated. They had to look official, and looking official has never been cheaper.

You cannot harden other people's inboxes. You cannot audit who has asked for your data, because no law makes them tell you. What you can control is narrow, and it is worth doing anyway. Verify every notice through a channel you opened yourself. Refuse every helper who finds you first. Hand each company less of yourself, and assume the file they keep will one day be pried loose by someone holding a forged badge.

This week the government was asking. Next week it will be your bank asking. Teach yourself that both can be lying, and check.

Stay sharp. Trust slowly. Verify everything.

◆ QUICK REFERENCE
How This Breach Worked
A fraudulent request from a real government email domain, not a hack
It passed SPF, DKIM, and DMARC, which prove the mailbox, not the authority
Aimed at high net worth customers, a shopping list, not a random dump
Exposed passports, selfies, addresses, IBANs, and full Bitcoin histories
Do This If You Are Exposed
Verify any breach email through the app or the number on your card, never its links
Ignore anyone who emails to recover your funds, and report it to ic3.gov
Move crypto to addresses never linked to the leaked accounts
Freeze credit at all six bureaus and treat leaked wealth as a safety risk
What People Miss
US law lets companies share data with no judge under the emergency exception
A request can come from any of 18,000 jurisdictions and rarely gets verified
You are only as safe as the least careful company that holds your data
The real breach notice and the phishing notice land in the same inbox
Sources
TechCrunch, "Revolut confirms customer data breach through fake government requests," September 12, 2026.
Help Net Security, "What we know about the Revolut data breach so far," September 14, 2026.
The Crypto Times, "Revolut Hackers Begin Leaking Customer Passports and Selfies," September 14, 2026.
Kodex, "Fraudulent Emergency Data Requests (Fake EDRs)."
Bloomberg and KrebsOnSecurity reporting on forged emergency data requests, March 2022; FBI public service advisory on law enforcement email compromise, November 2024.
◆ SPREAD THE SIGNAL

The next email from your bank might not be from your bank.

Someone you know is going to get a breach notice this year, panic, and click the first link that promises to help. Send them this before that day, and teach them the one habit that survives every version of this: never act on a message about your money until you have opened the app or dialed the number on your card yourself.

SEND THEM THE DEAD DROP
EYES ONLY.
FORWARD WITH CARE.
◆ CLASSIFICATION · EYES ONLY ◆
Disclaimer
 

The material contained in these newsletters examines techniques developed for high-stakes environments, including intelligence operations, law enforcement, investigations, negotiation, and human-source engagement. Such methods do not exist outside the law. Their legitimate use is constrained by professional ethics, established safeguards, human rights protections, and the legal authorities governing the person who employs them.

Knowledge is not authorization.

Nothing contained here should be interpreted as permission to manipulate, coerce, deceive, intimidate, exploit, or harm another person. Psychological influence techniques can produce consequences far beyond the intention of the person who applies them. Misuse may result in civil liability, criminal exposure, professional sanction, reputational ruin, or consequences that cannot be reversed once set in motion.

This material is provided solely for education, ethical analysis, professional awareness, and baseline reference. The author and publisher accept no responsibility for actions taken, omitted, improvised, or rationalized by the reader.

 

Some doors are described so that you may recognize them.

That does not mean you should open them.