- Revolut confirmed it handed sensitive customer identity documents and Bitcoin transaction records to an unauthorized party after fraudulent requests passed legitimate email authentication checks, according to the company.
- The exposed data may have included passport copies, verification selfies, account statements, IBANs, and full cryptocurrency transaction histories, Revolut says, though the customer count remains undisclosed.
- Blockchain investigator ZachXBT first surfaced the incident publicly, and unconfirmed chatter from ZachXBT suggests high-net-worth individuals may have been targeted — a claim Revolut has not verified.
What Folks Are Sayin' Down at the Feed Store
Well, grab yourself a cold RC Cola and sit down, because this one is a doozy. Revolut — the British fintech outfit that's fancier than a new tractor at a county fair — has confirmed, according to the company's own disclosure reviewed by TechCrunch, that it handed over sensitive customer information to an unauthorized third party. The company says the culprit pulled it off by firing off data requests from a real government agency's email domain, dressed up slicker than a coyote in a henhouse. Revolut says the scheme was a sophisticated external impersonation effort, not a direct hack into its own systems.
Blockchain investigator ZachXBT — who has a nose for these things sharper than a hound dog on a ham bone — first dragged this into the daylight by sharing a copy of Revolut's customer notification letter on Telegram. Adding fuel to the gossip fire, former Mt. Gox CEO Mark Karpelès went and posted excerpts of a similar notification he received on X, independently confirming that at least some customers were getting these letters. CoinDesk and CyberSecurityNews both picked up the story on September 12, 2026, giving it legs beyond just social-media chatter.
What We Actually Know for Sure
Revolut confirmed to TechCrunch — and that confirmation is about as close to gospel as we're gonna get here — that it did indeed disclose customer data after receiving fraudulent government-style data requests. The company says the exposed information included identity and contact details such as birth dates, postal addresses, email addresses, and phone numbers, along with copies of identity documents like passports and driver's licenses. Revolut further says the breach may have also swept up verification selfies, account statements, IBANs, and full Bitcoin transaction histories, though it used the word 'may' like a man hedging his bets at a church raffle.
According to reporting by CyberSecurityNews and CryptoSlate, the fraudulent email cleared SPF, DKIM, and DMARC authentication — the three-legged stool of email verification that's supposed to keep the riff-raff out. The reason those checks passed, those outlets report, is that the attacker was operating from an unauthorized mailbox sitting inside a genuine government domain, rather than faking one from the outside. That's the difference between someone picking your lock and someone who already has a key to the building. Revolut says its own internal systems and customer funds were not compromised; this was a procedural fumble in its government-request verification process, not a break-in.
Security analysts cited by Glitchwire and CybersecurityNews note this attack vector — abusing so-called emergency data request channels — has been a documented threat since at least 2022. The analysts say domain authentication standards alone are as useful as a screen door on a submarine when the attacker is already operating from inside legitimate government email infrastructure. An emergency data request, for those unfamiliar, is a law enforcement ask that companies are expected to answer quickly on grounds of imminent danger, without a court order and with less scrutiny than normal.
What Nobody's Been Willing to Fess Up To
Now here's where the mud gets real thick. Revolut has not named which government agency's domain was used, citing an active police investigation — which is fair enough, but it leaves a barn-sized hole in the story. The company has not disclosed how many customers were affected, describing the impact only as 'limited,' which is the corporate equivalent of saying your barn fire was 'manageable.' No independent source has produced an actual headcount, according to TechCrunch and The Coin Republic.
Whether the attack involved a compromised government mailbox, a rogue insider with authorized access, or some other method of getting into that domain's email infrastructure has not been established. Revolut declined to explain the mechanism to any outlet. The scope of which markets or geographies were hit is also unknown. ZachXBT suggested, based solely on his review of notification letters shared on Telegram, that the breach appeared to target high-net-worth individuals — but that is ZachXBT's interpretation alone and Revolut has not confirmed the profile of those affected, according to CoinDesk and AMBCrypto.
CoinDesk floated the idea that this attack may have involved AI-assisted impersonation techniques, but no other outlet corroborated that framing, and it reads more like editorial inference than a confirmed technical finding. Treat that particular claim like a catfish at a bass tournament — it might technically qualify, but something ain't quite right about it.
Why This Mess Is Particularly Gnarly for Crypto Folks
Here's the part that ought to make any Bitcoin holder sweat through their overalls. Bitcoin transactions are public — anybody can see money moving on the blockchain — but wallet addresses are not normally connected to a verified real-world identity. The whole point of KYC at a fintech company is that it holds that linking information: the bridge between a wallet address and a human being's face, passport, and home address. According to analysis from AMBCrypto and CryptoSlate, whoever got their hands on this data now potentially holds both ends of that bridge, meaning they can match on-chain transaction histories to physical identities and home addresses. That is precisely the kind of information that could make a wealthy crypto holder a target for everything from phishing to something considerably more unpleasant.
It is also worth noting — and multiple outlets including AMBCrypto and Yahoo Finance flagged this without implying any causal connection — that this incident occurred close in time to the U.S. Office of the Comptroller of the Currency granting Revolut conditional approval to establish a U.S. national bank. No source has alleged any link between those two events, and we are not drawing one either. It is just the kind of timing that makes a man go 'hmmm' while he's staring at the ceiling.
Analysis: The Verification Hole Is Bigger Than One Company's Problem
This is analysis, not reporting, so label it accordingly: the real trouble here is that Revolut did more or less what it was supposed to do. It checked whether the email came from a legitimate government domain — and it did. SPF passed. DKIM passed. DMARC passed. The system worked exactly as designed and still delivered customer data straight to a fraudster, like a well-trained retriever fetching a stick for the wrong hunter. That suggests the vulnerability is not a bug in Revolut's process so much as a systemic gap in how the entire financial industry handles government data requests when the threat is an insider operating within legitimate infrastructure.
Security researchers have been hollering about emergency data request abuse since at least 2022, according to Glitchwire and CryptoTicker, and major tech platforms have already dealt with documented cases of attackers compromising law enforcement email accounts to make fraudulent requests. Financial institutions that hold KYC data alongside cryptocurrency transaction histories represent a particularly rich target because the payoff — linking anonymous blockchain activity to verified human beings — is exceptionally valuable to bad actors. Until regulators or the industry settle on out-of-band verification requirements for sensitive data disclosures, any company relying solely on email authentication is essentially leaving the front door unlocked and trusting that only police officers will knock.
Who is doing the hollering
These links show where the chatter came from. A link is attribution, not our endorsement or independent confirmation.
- Revolut confirms customer data breach through fake government requestsTechCrunch · top tier
- Revolut confirms customer data breach through fake government requestsYahoo Finance / TechCrunch · top tier
- Revolut handed customer data to fraudsters using a government email domainCyberInsider · specialist
- Bitcoin activity, passports exposed after Revolut falls for fake government requestCoinDesk · specialist
- Revolut Data Breach Exposes Customers' Passport Copies and Full Transaction Histories to HackersCyberSecurityNews · specialist
- Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customersCryptoSlate · specialist
- Revolut: Revolut Gave Customer Data to Scammers After Fake Government RequestsRankiteo Blog · specialist
- Revolut Handed Over Passports, Bitcoin Records After Fake Government Request Slipped Through Email AuthenticationGlitchwire · specialist
- Fake government request exposes Revolut's customer data and Bitcoin historiesAMBCrypto · specialist
- Revolut Crypto Scam: Fake Government Request Exposes Bitcoin User DataThe Coin Republic · specialist
- Revolut Data Breach: Am I Affected and What To Do?CryptoTicker · specialist
Last checked Sep 13, 2026, 9:07 AM EDT. Talk Around Town: Key facts remain undisclosed: Revolut has not named the government agency, has not revealed the number of affected customers, and has not explained whether the agency's email infrastructure was compromised or an inside account was abused. The scope, geography, and downstream use of the stolen data are unknown. Handle with caution — particularly claims about 'high-net-worth targeting,' which come solely from ZachXBT and are unconfirmed by Revolut.