Highlights
Digital banking platform Revolut mistakenly disclosed customer information after receiving a fraudulent request disguised as an official government document. The fraudulent email originated from a legitimate agency domain name and successfully passed the authentication protocol. The leaked information included personal identifiers, passport documents, verification photos and financial statements. Bitcoin wallet identifiers and complete cryptocurrency transaction records were also among the leaked materials. Blockchain investigator ZachXBT said the scope of the leak appears to be limited and may mainly target wealthy account holders.
Financial technology giant Revolut inadvertently shared sensitive customer information with illegal recipients after receiving a seemingly real government data request. The fraudulent communication came from a genuine government agency email domain name and successfully passed the standard domain name verification protocol.@ Coin Bureau (@coinbureau) September 12, 2026
Scope of disclosure
According to Revolut, the organization processed the request based on its apparent legitimacy. The company declined to say which government agency's domain name was used, nor did it provide details on how unauthorized individuals could access official channels.
The data breach involved a wide range of personal and financial details. Customer information, including full full names, date of birth, occupation, residential address, email contact information and telephone numbers, was leaked.
Official identification materials, such as copies of passports and driver's licenses, form part of the disclosure, and also include verification selfies provided by customers during the account opening process. The company emphasized that biometric facial recognition data remains safe.
Bank records are an important part of exposed materials. The illegal recipient obtained account statements, International Bank Account Numbers (IBAN), account creation dates, withdrawal logs and comprehensive transaction ledgers.
Information related to cryptocurrencies featured prominently in the leaked statement. The Bitcoin wallet reference code is visible in the account file. Complete Bitcoin transaction logs were also transmitted, raising concerns about the privacy of cryptocurrency holders, as their financial flows can now be traced to their real-world identities.
The company confirms that the encrypted private key, login credentials and complete bank card number are protected and were not included in unauthorized disclosures.
Affected user groups
Blockchain investigator ZachXBT issued a customer notice via Telegram on September 11. His assessment suggests that the scope of the incident was relatively narrow and may have targeted wealthy account holders specifically. Revolut has not disclosed the specific number of customer accounts affected.
The platform has more than 80 million users worldwide. This number represents the total number of registered accounts in all markets, rather than the subset affected in this security incident.
The customer consultation did not clarify whether all compromised accounts contained the same data category, nor did it explain the selection criteria for individuals.
Compliance and Security Impact
According to the UK Information Commissioner's Office, data security failures can lead to identity theft, fraudulent activity and financial loss. The regulatory framework requires organizations to report eligible violations within 72 hours and notify affected people with reasonable delay.
The picture of the notice distributed by ZachXBT did not show whether Revolut had filed a mandatory regulatory report, nor did it specify when the company discovered the fraudulent nature of the request.
Revolut maintained public silence about the incident except for customer notification. The company did not disclose which government entities had their email infrastructure compromised.
The security breach occurred during Revolut's business expansion initiative. On September 3, the company received a provisional banking charter from the Office of the Comptroller of the Currency. In addition, Revolut launched the euro-denominated stablecoin EURR to its selected European customers in August.
These business developments have nothing to do with data breaches. Revolut did not say any of the affected people had U.S. based accounts.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC