EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Revolut: False requests lead to Bitcoin history and ID disclosure

2026-09-13 18:22:16
Bookmark

Revolut confirms customer data breach: Identity documents and Bitcoin transaction records were illegally obtained

Revolut has confirmed that a customer data breach occurred. According to reviewed customer notices, after receiving fraudulent information requests sent using legitimate government agency email domain names, identity documents and some customers 'Bitcoin transaction histories were handed over to unauthorized third parties. The incident highlights a long-standing contradiction faced by Bitcoin holders: exchanges and new banks maintain detailed records that directly link personal identities to financial activities on their chains.

Summary of Key Information

Revolut confirmed that identity and contact details, including financial records (reportedly containing Bitcoin activity), had been released to a third party posing as a government requester. Currently, the exact number of customers affected, the institutions being impersonated, the scope of the market involved and the specific date of the fraudulent disclosure have not been disclosed.

Details on Revolut's Bitcoin Data Disclosure Statement

A spokesperson for Revolut told the media that an unauthorized third party obtained sensitive customer information through fraudulent requests from the email domain name of a legitimate government agency. The media reviewed notices sent to affected customers.

The leaked data listed in the notice includes identity and contact details such as birth dates, postal and email addresses, phone numbers, and copies of passports or driver's licenses. Revolut's notice also stated that verification selfies, account statements and transaction history may also be included, but the wording was carefully worded and did not confirm that all fields for each affected customer had been compromised. According to Decrypt, another media outlet, the leaked financial records described the IBAN number, wallet reference number, withdrawal records and complete transaction history, including Bitcoin transactions. This detailed range of Bitcoin data is attributed to the content of the notification in the report rather than the results of independent forensic investigations, and the exact range of data lost to each customer is unclear.

Currently, existing reports have not established the specific number of customers affected, the date of the incident and the jurisdictions involved. Although various parties have consistent descriptions of how Revolut exposed KYC and Bitcoin data in the reports, the specific quantitative issue has not been resolved, and readers should regard the precise scope of influence as undecided.

Questions about alleged forged government requests

The current reported sequence of incidents is "fraudulent requests subsequently leading to data disclosure," which is a timeline description rather than a verified technical explanation that cannot explain how the release was authorized. The legal government mailbox domain name alone does not prove that there is a valid legal requirement. The specific legal basis and request verification process behind this disclosure are still unknown.

Details such as the claimed authoriser, submission channel, request for authentication, and internal release authorization still need to be corroborated. There are currently no independent forensic reports that determine how government domain name email accounts were used or which controls failed, so there is no basis for claiming that domain names were spoofed or servers were compromised.

Revolut said its systems and client funds were not affected, but this was only a company statement and not the result of an independent audit. The company also said that after discovering the scam, it blocked the email address and notified relevant government agencies, law enforcement and regulatory agencies; but did not specify specific authorities and did not establish specific regulatory penalties for the incident.

Revolut told media that the number of customers affected was limited and had contacted them directly, but did not disclose the exact number. When media reports confirmed the matter, they pointed out that online investigator ZachXBT released the content of customer emails on Friday, but the report did not lock in the exact time of the fraudulent disclosure. Similar reports detailing how Revolut disclosed Bitcoin history after false requests also preserved these gaps.

According to unconfirmed reports, the incident specifically targeted high net worth customers, an assessment attributed to ZachXBT and not confirmed by Revolut. There were also unconfirmed reports that the full Bitcoin transaction history and verification selfies of each affected customer were disclosed, but the report used the phrase "may contain" and did not establish an individual scope.

Privacy impact on Revolut Bitcoin users

Linking government-issued identity documents to records of Bitcoin activity is precisely what creates privacy risks and targeted phishing risks, because it ties real-world identities to financial records. These are conditional risks arising from data categories, rather than actual consequences observed in this event.

Existing materials do not confirm the disclosure of login credentials or private keys, account takeover or any loss of Bitcoin. This difference is important: the custody identity record is different from the encryption key that controls the coin, and the reported presence of the wallet reference number in the notification is not evidence that any Bitcoin was transferred. The leak about how Bitcoin wallets were linked to home addresses illustrates concerns about de-anonymization, but does not prove downstream theft.

For anyone concerned about this issue, general precautions still apply. Recommendations from the UK's Information Commissioner's Office (ICO) include checking bank statements and credit files, verifying accidental connections through known official channels rather than links in messages, and considering registering a CIFAS-protected register for additional checks in financial applications. Customers should rely on official communications within the app and contact support services through official channels for any suspicious requests, separating these steps from specific event instructions that Revolut has not yet released.

For Bitcoin holders, this incident reaffirms the basic principle of distinguishing the network's basic layer from its upper custody layer. The security of the underlying protocol, from proof-of-work issuance to self-custody through private keys, is not affected by data leaks from financial institutions; the exposure here is a recording issue, which also reminds people that KYC data retained under the chain is still an ongoing responsibility that cannot be repaired through difficulty adjustments.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP