Data Analytic Investments
RIPPLE book coverRIPPLE — the book·numbered first edition·$9.99Buy now
Research

Revolut handed customer passports and Bitcoin transaction histories to a fake government request: what is confirmed, what is not

On 12 September 2026 Revolut confirmed that an unauthorised third party used a legitimate government agency email domain to submit fraudulent data requests, and that the company answered them. Identity documents, selfies, addresses, account statements and Bitcoin transaction histories of a 'limited' number of customers were handed over. This is a documentary record of what Revolut said, what the researcher who first reported it said, and what remains unknown.

D
DAI Research Desk
5 min read
Revolut handed customer passports and Bitcoin transaction histories to a fake government request: what is confirmed, what is not

On Friday 12 September 2026 the fintech company Revolut confirmed a data breach of an unusual kind. Nobody broke into its systems. Instead, according to the company's own description, someone sent it official-looking requests for customer information from a genuine government agency email domain, and Revolut answered them. This article records what has been confirmed, by whom, and what has not.

🎧 Audio edition — the full article read aloud, 7 minutes, MP3: revolut-fake-government-request-2026-09-audio-EN.mp3

What Revolut said

TechCrunch published the company's statement on 12 September. Revolut described the incident as "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests." The company added that "Revolut systems and customer funds are unaffected." It said a "limited" number of customers were affected, and it declined to say how many, or in which market. It said it had notified the relevant government agency, law enforcement and financial regulators. CoinDesk reported the same day that affected customers and regulators had been notified.

What was handed over

The categories of data listed in the reporting, drawn from Revolut's customer notification, are these. Identity and contact details: names, dates of birth, postal addresses, email addresses, phone numbers and, according to CoinDesk, occupations. Copies of identity documents — passports and driving licences — and the verification selfies taken during onboarding. Account statements and IBANs. And, for customers who used Revolut's crypto services, transaction histories, which CoinDesk describes as full Bitcoin transaction records and withdrawal records.

The combination is the point. A passport scan on its own is one problem; a Bitcoin transaction history on its own is another. Together with a home address and a selfie, they connect a person, a face, a front door and a set of on-chain transactions in a single file. TheStreet's headline on 12 September put it bluntly: the leak "ties Bitcoin wallets to home addresses".

Who reported it first

The incident became public through the blockchain investigator known as ZachXBT, who posted about it on Friday before the company's confirmation. TechCrunch quotes him saying the breach "appeared to have been targeted at high net worth users"; CoinDesk, citing his Telegram broadcast, quotes that it "appeared limited in size and may have targeted high-net-worth users." Revolut's statement neither confirms nor denies the targeting; it uses only the word "limited".

How the mechanism works — as far as the sources describe it

Banks and payment companies receive lawful requests for customer data from courts, tax authorities, police and financial regulators. Those requests arrive by email, often from official domains. The reporting indicates that in this case the sender's address genuinely belonged to a government agency domain — Revolut's word is "legitimate" — but the person behind it was not authorised to make the request. CoinDesk frames the weakness as an authorisation failure: the request looked like it came from the right place, and the check that it came from the right person did not catch it. Neither outlet names the agency or the country, and Revolut has not done so either. We therefore do not name one.

What is not known

Five things are open as of the morning of 13 September. The number of customers affected. The market or markets involved. The agency whose domain was used, and how the sender obtained access to it. Whether the data has appeared for sale or been used. And what Revolut has told affected customers to do — the reporting we have seen quotes no specific guidance. Where a later statement fills any of these gaps, this article should be read against it.

Why it matters beyond Revolut

Every regulated crypto service in Europe collects the same package — identity document, selfie, address, transaction history — because the rules require it. That package exists at every exchange and every bank with a crypto product. The Revolut case shows one way it leaves the building: not through a hack, but through a request that looked legitimate. For anyone who holds crypto through a regulated intermediary, the practical reading is that the security of your identity data depends on that intermediary's process for verifying who is asking, not only on its firewalls.

We do not hold customer funds or customer identity documents — our company is a data and education service, described on the About page — but we teach how these systems work. The Crypto Academy covers what an exchange knows about you and why; our earlier article on Anthropic's threat intelligence report documented how impersonation is used at scale. Live, sourced market data — not personal data — is what we publish on Market Observation.

Sources

  • TechCrunch, Jagmeet Singh, "Revolut confirms customer data breach through fake government requests", 12 September 2026, 7:40 AM PDT — Revolut's statement quoted verbatim; data categories; "limited" number of customers; notifications.
  • CoinDesk, Shaurya Malwa, "Bitcoin activity, passports exposed after Revolut falls for fake government request", 12 September 2026, 10:11 AM (updated 10:50 AM) — ZachXBT's Telegram statement; data categories including Bitcoin transaction and withdrawal records, occupations, IBANs.
  • The Block, "Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov't domain", 12 September 2026.
  • TheStreet, "Revolut leak ties Bitcoin wallets to home addresses", 12 September 2026.

Educational content. Not investment advice.

Explore Topics

#Revolut#data breach#Bitcoin#KYC#privacy#security#impersonation#fintech
D

Written by

DAI Research Desk

Content creator and writer sharing insights and stories.

Share · Megosztás:XFacebookLinkedInWhatsAppTelegramE-mail

Related Research

Moscow Exchange lists perpetual futures on five crypto indices from 22 September: what the exchange notice says, and what it does not
Research

Moscow Exchange lists perpetual futures on five crypto indices from 22 September: what the exchange notice says, and what it does not

On 16 September 2026 Moscow Exchange announced five perpetual futures with daily auto-rollover on its own Bitcoin, Ether, Solana, XRP and Tron indices, launching 22 September, cash-settled in roubles, for qualified investors only. This article documents the notice line by line: the contracts, the settlement design, the funding parameters, the exchange's own usage figures since 2025, and the questions the notice leaves open.

5 min readDAI Research Desk
#Moscow Exchange#MOEX#perpetual futures
South Korea's central bank digital currency, Project Hangang: nine banks, 500 thousand wallets, and an opposition leader's privacy warning — what is documented
Research

South Korea's central bank digital currency, Project Hangang: nine banks, 500 thousand wallets, and an opposition leader's privacy warning — what is documented

On 14 September 2026 the leader of South Korea's opposition People Power Party said he 'strongly opposes' introducing a CBDC until legal safeguards are in place. This article sets his statement against the record of Project Hangang: two pilot phases, seven then nine banks, up to 500 thousand wallets, and a wholesale design that never gives consumers a central-bank account.

5 min readDAI Research Desk
#CBDC#South Korea#Bank of Korea
Symbiosis Bitcoin bridge exploit: 46 billion fake syBTC minted, 336 thousand dollars taken, 15 BTC recovered — what the record shows
Research

Symbiosis Bitcoin bridge exploit: 46 billion fake syBTC minted, 336 thousand dollars taken, 15 BTC recovered — what the record shows

On 11 September 2026 a flaw in Symbiosis's BridgeV2 contract on BNB Chain let an attacker mint roughly 46 billion unbacked syBTC. The realised damage was about 336 thousand dollars; the protocol says it recovered about 15 BTC and offered a 20 percent bounty. This is a dated record of what happened, what was recovered, and what is still paused.

5 min readDAI Research Desk
#Symbiosis#bridge exploit#Bitcoin