After the Leak: Your Password Can Change. Your Passport Can't.
LEAKLENS EXPLAINER · SEPTEMBER 2026
# After the Leak: Your Password Can Change. Your Passport Can't.
The FBI got a ransom note that doesn't ask for money. Revolut got robbed by an email that broke no rules at all. Here's where the data goes next — and why one of these leaks should worry you even if you've never used either service.
2–3TB — data ShinyHunters claims to have taken from the FBI's jobs portal ~680 — Revolut customers reportedly affected, per one outlet's reporting; Revolut itself has not confirmed a number $20–100 — typical dark-web price for a "fullz" identity package, the market Revolut's leak feeds into 1 week — ShinyHunters' deadline for the FBI. Not to pay. To retract, publicly, a statement calling them liars.
Editorial note: these are two unrelated incidents. We're covering them together because they're a useful pair for a question that gets skipped in most breach coverage — not "what leaked," but "what happens to it after." The FBI case shows the classic extortion pipeline with an odd twist; the Revolut case shows exactly which underground market a KYC-document leak feeds, and why that market is bigger and cheaper than most people assume.
The short version
The FBI called a hacking group a bunch of exaggerators. The hacking group's response: retract that statement within a week, or 2–3 terabytes of agents' psychiatric records and their families' home addresses go public. Not for money — for a retraction.
Eleven days earlier, and in a completely different corner of the fraud world, Revolut handed over customer passports, KYC selfies, and crypto wallet data to an attacker — not because anyone hacked a server, but because the request came from a real government mailbox, and Revolut is legally obligated to answer it.
Same month, same word — "breach" — two completely different machines starting up. One runs on threats. The other runs on a resale market you've probably never heard of, and it doesn't care whether you've ever opened a Revolut account.
Case 1: When the Ransom Note Doesn't Want Money
Picture the position ShinyHunters is actually in: they say they're sitting on 2 to 3 terabytes taken from the FBI's own jobs portal — including, they claim, mental-health records with real names attached, and a sample batch of 5,000 files with home addresses and family details already shared with reporters as proof. That's not really a "breach" in the ordinary sense anymore. It's a hostage situation, conducted entirely through email and Telegram.
This group has done this before — a lot. Since 2020, researchers count somewhere between 300 and 400 organizations run through the same pipeline: get in, take everything of value, quietly ask for money, and if the money doesn't come, make it everyone else's problem by dumping the files publicly or auctioning them off. It's worked often enough that AT&T once paid $370,000 just to make a pile of stolen call records disappear — and even that didn't necessarily mean the data was gone for good.
What makes the FBI case strange is what ShinyHunters is actually asking for. Not money. A retraction — a public, on-the-record admission that the bureau was wrong to call them exaggerators, issued within a week, or the files go out. Researchers watching this have called it "reputational warfare dressed up as a data breach," which is a fair description of a group that usually wants a wire transfer suddenly wanting a public climbdown instead.
If the week runs out, history isn't encouraging. Groups like this have leaked data even after being paid, so there's no version of this where compliance guarantees safety — only a version where non-compliance guarantees exposure. And if the health records are real, the damage isn't primarily financial. It's a named agent's psychiatric history sitting in public, a home address next to their kids' names. That's a fundamentally different kind of harm than a stolen credit card number — closer to a threat against a person than a hit to a balance sheet.
Case 2: The Breach Where Nothing Was Hacked
Nobody hacked anything.
The Revolut story starts somewhere much quieter than a hacker's ransom note: an email. Someone got into a mailbox that genuinely belonged to a government agency — real domain, real authentication, nothing about it technically wrong — and used it to ask Revolut for customer records. Revolut looked at the request, saw a legitimate government address behind it, and handed the data over. No malware, no breached server, no alarm bells. Just a request that looked exactly like the ones Revolut is legally required to honor.
What went out the door: passport photos, driving licences, the selfies people take holding up their ID to prove they're a real person, account statements, transaction history down to individual Bitcoin trades, IBANs, and wallet reference numbers.
Here's the part that's easy to miss: none of that data is primarily useful for emptying the Revolut account it came from. It's useful somewhere else entirely. A passport scan and a matching selfie are the two things almost every bank, exchange, and fintech asks for before letting a stranger open an account — and there's a thriving, cheap market built entirely around selling exactly that combination. Researchers price a basic identity package, name and address and a document scan, at $20 to $100 on dark-web markets.
A passport scan and a matching selfie are the two things almost every bank, exchange, and crypto platform asks for before trusting a stranger with money. Yours is now for sale — for less than a dinner out.
Fifteen dollars, in some cases, buys a forged passport good enough to fool an automated check on its own — pair that with a real stolen photo and a real stolen document, and the fraud gets harder to catch, not easier, because the document itself isn't fake anymore.
Some tools now feed a fake face into a live ID check in real time. Pair that with a real stolen passport, and the fraud gets harder to catch — because the document isn't fake anymore. Only the person holding it up is.
The account-opening date and the wallet reference number in the leak aren't throwaway fields either — they're exactly what a smooth-talking fraudster needs to sound convincing when they call a support line pretending to be the customer. The wallet reference in particular is what ties someone's ordinary bank account to their crypto holdings — a single number that turns two separate identity thefts into one.
And this isn't a one-off for Revolut. Earlier this year: an ex-employee threatened to leak KYC data. A forum post claimed 75 million records for sale (likely fabricated, but still). A wave of scam calls impersonating Revolut's own fraud team cost people in Jersey roughly £180,000. This fake-government-email incident is the fourth KYC-adjacent story involving the company in 2026 — a pattern, not a random unlucky month.
Same question, two different answers
Line them up side by side and the difference stops being abstract:
| | FBI / ShinyHunters | Revolut | |---|---|---| | What the data becomes | Leverage — a threat used for a specific demand | Raw material — feedstock for fraud against other institutions | | Who benefits from a leak | The group extorting the victim directly | A wider resale market of unrelated fraudsters | | Immediate harm to individuals | Harassment, doxxing, reputational/psychological exposure | Identity-fraud exposure at services you've never used | | Does paying/complying stop it | No — the group has a track record of leaking anyway | Not applicable; Revolut already handed the data over voluntarily, believing the request was legitimate | | What you can do ahead of time | Little — this depends on your employer's data handling, not yours | Flag your identity for extra verification with banks/exchanges you use, before a fraudster gets there first |
A password reset takes thirty seconds. A passport doesn't reset — ever. If yours was in this leak, that document is compromised for the rest of your life, not just this news cycle.
What to do if you're affected by either kind of leak
If your data was in a leverage-style breach (like the FBI case):Sources:
- Washington Post — original FBI breach claim report
- NBC News — FBI statement, ShinyHunters' PSA-retraction demand
- Federal News Network — Oracle PeopleSoft vector claim, FBI's "historical... no government information" characterization
- Al Jazeera — FBI's prior public characterization of ShinyHunters' tactics
- Huntress — ShinyHunters Threat Actor Profile — group's operating model, prior campaigns (Snowflake/AT&T, Salesforce)
- TechCrunch, via Yahoo Finance — Revolut's confirmation and direct customer notification
- The Register — independent confirmation, ransom demand detail
- Zyphe — GDPR liability analysis, what was in the customer notice
- TheCyberSecGuru — Revolut's prior 2026 KYC-related incidents timeline, wallet-reference/social-engineering analysis
- Zyphe — Fullz and Synthetic Identity Fraud in 2026 — dark-web fullz pricing
- Privacy Insight Solutions — OnlyFake and deepfake KYC-bypass tooling