EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Revolut data breach: Passport and Bitcoin records reportedly exposed

2026-09-13 12:31:35
Bookmark

Revolut confirms data breach: Passport and Bitcoin transaction records were reportedly exposed to third parties

Financial technology company Revolut has confirmed a data breach that resulted in customer passports, identification documents and financial records (reportedly including Bitcoin transaction history) being obtained by an illegal third party disguised as a government agency. The company said the leak was caused by receiving a fraudulent request from a legitimate government mailbox domain name. The impact of this incident is spreading rapidly among the most privacy-minded circles in the cryptocurrency space.



Disclosure of details and scope of influence

On September 12, 2026, Revolut confirmed to the media that it had released customer information after receiving emails that appeared to come from real government agencies. This incident did not involve the firewall being breached or the password being cracked, but the attacker induced the operation through very convincing means. Revolut emphasized that its system security and customer funds were not affected. This distinction is crucial: this was a data disclosure incident, not the theft of wallet funds. Given the company's recent aggressive expansion of its presence in the crypto space, including the launch of EURR stablecoins, the exposure of financial records is particularly sensitive.



Specific content of leaked data

The customer notices reviewed listed a range of in-depth identifying information, including dates of birth, postal and email addresses, phone numbers and copies of passports or driver's licenses. The notice also noted that verifying selfies, account statements and transaction history may also be included. However, it should be noted that these categories are marked as "potentially affected" and that this information is not generally exposed for all customers.

Details about Bitcoin come from Decrypt's report. The report stated that the financial records described in the notice included IBAN numbers, wallet reference numbers, withdrawal records and a complete transaction history, including Bitcoin transactions. However, this specific detail has not been independently verified based on the original notice.

It needs to be clear that there is currently no evidence that Bitcoin funds, private keys, passwords or account access rights have been compromised. What is leaked is information, that is, information that allows others to understand your identity and assets, rather than direct control of assets.



How to forge a government request opens a gap

The core charge is based on a single mechanism: the request is forged. Revolut said fraudulent messages came from legitimate government agency email domain names, which made them convincing enough to be enforced. In addition, the situation is described briefly. Revolut does not specify the impersonated authority, jurisdiction, request channel or how its verification process handles the request. These procedural details should not be arbitrarily assumed.

An unproven theory holds that a valid domain name certificate explains why Revolut executed the request. Decrypt described this possibility, but according to unconfirmed reports, email headers, certification results and technical post-mortem analysis reports were never made public. Useful background information is provided here: Email authentication standards such as SPF, DKIM, and DMARC are used to verify that a message really comes from the domain name it claims to be. However, inspection only proves the source of the email and does not indicate whether the sender has the right to request customer records. These are two independent decision-making processes, and confusing the two is the reason why identity fraud is successful.



Issues that have yet to be clarified

Reval told the media that a small number of customers have been affected and have contacted directly, but declined to disclose the exact number of people, the government agencies involved, or whether the leaks were limited to specific markets. The company said it had blocked relevant email addresses and notified relevant government agencies, law enforcement agencies and regulatory agencies, but did not specify the specific targets and has not established any regulatory investigations, enforcement actions or fines.

According to unconfirmed reports, online investigator ZachXBT assessed that the incident targeted high-net-worth users, and this assessment was attributed to him by the media. Since the original investigation post or target evidence was not obtained, it should be regarded as clues rather than established facts.

The potential consequences are obvious: Identity theft and financial privacy risks exist for people whose passports and assets may fall into the wrong hands. These are risks, not observed results. There have been no confirmed fraud, theft of funds or personal injury related to this leak.



Industry response and market response

For cryptographic users, this leak rekindled dissatisfaction with mandatory identity collection. Marc Zeller, founder of the Aave Chan Initiative, said his data had been compromised and used the opportunity to attack KYC (Know Your Customer) data retention practices. He wrote on social media: "I woke up and found my data had been leaked by @Revolut. This is a sharp reminder that KYC has not brought substantial benefits and has put many people at risk."

His view is a sharp opinion, not a forensic conclusion. But this resonates against the backdrop of markets already uneasy about custody and disclosure risks, and a similar theme has been reflected in recent stories such as Blockstream's refusal to pay ransom for the Liquid Bitcoin hack and the SEC's reported shelving of a crypto framework meeting.

Bitcoin itself has almost no fluctuations. The asset was trading at close to US$77,338, down approximately 0.5% on the day, and there was no price reaction directly related to the event. The story is about data, not price.

So the core question hanging over the industry is: If a well-resourced fintech company can be manipulated by social engineering through a seemingly trustworthy email to hand over passports and transaction history, then who is protecting the identity data that KYC rules force everyone to submit?

Disclaimer : This article is for reference only and does not constitute financial or investment advice. There are significant risks in the cryptocurrency and digital asset markets. Be sure to study for yourself before making a decision.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP