EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Revolut exposes Bitcoin records after false agency request

2026-09-12 18:30:25
Bookmark

Revolut disclosed some customers 'identity information and financial records for forging a request from a government agency.

Digital bank Revolut disclosed some customers' identity information and financial records, including Bitcoin transaction history. The data breach stems from the company's handling of a fraudulent request that appeared to be from a government agency.

Summary of the incident

Revolut stated that an unauthorized sender used the email domain name of an official government agency to send the request. Records disclosed include identification documents, selfies for verification and complete transaction history. In the notification sent to customers, the Bitcoin wallet reference number is listed on the account statement.

Online investigator ZachXBT pointed out that the impact of the incident appears to be limited and may mainly target high-net-worth users.

Attack methods and verification process

According to a Revolut customer notification shared by ZachXBT on Telegram, the request originated from an unauthorized email account using the domain name of an official government agency. The message passed a domain name authentication check, and Revolut said it believed the request was authentic when providing the information.

The notice did not specify the specific institution involved, nor did it explain how unauthorized senders obtained access to their mailbox domain name. In addition, the notice did not mention a specific date of the request or disclosure. ZachXBT said that multiple customers received alert emails on Friday, September 11, but neither he nor the notification section displayed in his posts gave a number of confirmations from affected users.

In Revolut's description of the incident, because the email carried valid domain name authentication credentials, it looked like a legitimate government request. The request was sent directly from an unauthorized account using the agency's official email domain name, rather than a fake email disguised as a similar address.

"Given that the communication carried valid domain name authentication credentials, the company complied with the requirement in the reasonable belief that it was requested by a real government agency." The notice read.

This wording describes unauthorized disclosure of data in response to a fraudulent request. The notice clearly stated that the intruder did not access Revolut's system, access customer accounts, or withdraw funds. The notice did not identify the sender and did not state whether relevant agencies had investigated the abuse of his email account.

Details of the information disclosed

Revolut lists the identification information provided including the client's full name, date of birth and occupation. Contact information includes postal address, email address and phone number.

The request also resulted in the disclosure of copied identification documents (such as passports or driver's licenses) and selfies provided by customers for identity verification. Revolut distinguished the images from biometric facial telemetry data it said was not involved.

Account statements constitute another part of the disclosed material. According to the notification, the statement contains IBAN (International Bank Account Number), account status, opening date and Bitcoin wallet reference number. Withdrawal records and a complete transaction history (including bitcoin transactions) are also provided.

The notice lists the types of information that may be disclosed, but does not establish that each affected customer has all types of records. At the same time, the notice did not state whether the wallet private key, account password or complete bank card details were included. Bitcoin transaction history is particularly critical to crypto users because notifications indicate that these records were sent to unauthorized recipients along with names and other account records.

According to Revolut's August announcement, it has more than 80 million customers worldwide. This figure reflects the size of its business rather than the number of users affected by this breach.

Potential impact on affected customers

The UK's Information Commissioner's Office (ICO) said possible consequences of personal data breaches include identity theft, fraud and financial loss. Its leak guidelines require an assessment of the information involved and an analysis of the harm individuals may suffer; but the guidelines do not establish that anyone has suffered such consequences in the Revolut incident.

For customers whose identity documents and transaction records were compromised, the notification indicates that the recipient may have obtained a detailed overview of the person's financial situation. ZachXBT's claim that wealthy users were targeted was not confirmed in the material presented by Revolut, which did not document subsequent abuse of the data.

Regulators 'guidance also stipulates that organizations must, where feasible, report certain personal data breaches within 72 hours of becoming aware of them, and notify individuals without undue delay when they pose a high risk to their rights and freedoms. The screenshot does not say whether Revolut has notified regulators or when the company first learned of the unauthorized request.

In its U.S. security guidelines, Revolut tells customers to use in-app support for Chat features to verify that suspicious contacts are authentic. The company said it would not ask customers to share verification or security codes over the phone. No such code was reported to have been leaked in customer notices displayed by ZachXBT.

Revolut's U.S. operations and cryptocurrency operations

This incident occurred while Revolut was expanding its banking and digital asset services. According to reports, on August 26, the company began providing its euro-anchored stablecoin EURR to some customers in Denmark, Poland and Portugal, and plans to further promote it in Europe. The launch of stablecoins has nothing to do with customer records leaks.

Although the notice did not identify any affected customers as located in the United States, Revolut's U.S. program provides background information to U.S. readers. On September 3, the company received conditional approval from the Office of the Comptroller of the Currency (OCC) for its Bank of America. Its proposed Stanford Bank of Connecticut will receive approximately $95 million in initial capital and is expected to open in 2027 if remaining approval is received.

Currently, according to early reports, Revolut provides U.S. banking services to customers through Lead Bank. The proposed national bank still needs to obtain deposit insurance from the Federal Deposit Insurance Corporation (FDIC), approval from the Federal Reserve and final authorization from the OCC before it can officially open.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP