Revolut handed customer passports and Bitcoin transaction histories to a fake government request: what is confirmed, what is not
On 12 September 2026 Revolut confirmed that an unauthorised third party used a legitimate government agency email domain to submit fraudulent data requests, and that the company answered them. Identity documents, selfies, addresses, account statements and Bitcoin transaction histories of a 'limited' number of customers were handed over. This is a documentary record of what Revolut said, what the researcher who first reported it said, and what remains unknown.

On Friday 12 September 2026 the fintech company Revolut confirmed a data breach of an unusual kind. Nobody broke into its systems. Instead, according to the company's own description, someone sent it official-looking requests for customer information from a genuine government agency email domain, and Revolut answered them. This article records what has been confirmed, by whom, and what has not.
🎧 Audio edition — the full article read aloud, 7 minutes, MP3: revolut-fake-government-request-2026-09-audio-EN.mp3
What Revolut said
TechCrunch published the company's statement on 12 September. Revolut described the incident as "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests." The company added that "Revolut systems and customer funds are unaffected." It said a "limited" number of customers were affected, and it declined to say how many, or in which market. It said it had notified the relevant government agency, law enforcement and financial regulators. CoinDesk reported the same day that affected customers and regulators had been notified.
What was handed over
The categories of data listed in the reporting, drawn from Revolut's customer notification, are these. Identity and contact details: names, dates of birth, postal addresses, email addresses, phone numbers and, according to CoinDesk, occupations. Copies of identity documents — passports and driving licences — and the verification selfies taken during onboarding. Account statements and IBANs. And, for customers who used Revolut's crypto services, transaction histories, which CoinDesk describes as full Bitcoin transaction records and withdrawal records.
The combination is the point. A passport scan on its own is one problem; a Bitcoin transaction history on its own is another. Together with a home address and a selfie, they connect a person, a face, a front door and a set of on-chain transactions in a single file. TheStreet's headline on 12 September put it bluntly: the leak "ties Bitcoin wallets to home addresses".
Who reported it first
The incident became public through the blockchain investigator known as ZachXBT, who posted about it on Friday before the company's confirmation. TechCrunch quotes him saying the breach "appeared to have been targeted at high net worth users"; CoinDesk, citing his Telegram broadcast, quotes that it "appeared limited in size and may have targeted high-net-worth users." Revolut's statement neither confirms nor denies the targeting; it uses only the word "limited".
How the mechanism works — as far as the sources describe it
Banks and payment companies receive lawful requests for customer data from courts, tax authorities, police and financial regulators. Those requests arrive by email, often from official domains. The reporting indicates that in this case the sender's address genuinely belonged to a government agency domain — Revolut's word is "legitimate" — but the person behind it was not authorised to make the request. CoinDesk frames the weakness as an authorisation failure: the request looked like it came from the right place, and the check that it came from the right person did not catch it. Neither outlet names the agency or the country, and Revolut has not done so either. We therefore do not name one.
What is not known
Five things are open as of the morning of 13 September. The number of customers affected. The market or markets involved. The agency whose domain was used, and how the sender obtained access to it. Whether the data has appeared for sale or been used. And what Revolut has told affected customers to do — the reporting we have seen quotes no specific guidance. Where a later statement fills any of these gaps, this article should be read against it.
Why it matters beyond Revolut
Every regulated crypto service in Europe collects the same package — identity document, selfie, address, transaction history — because the rules require it. That package exists at every exchange and every bank with a crypto product. The Revolut case shows one way it leaves the building: not through a hack, but through a request that looked legitimate. For anyone who holds crypto through a regulated intermediary, the practical reading is that the security of your identity data depends on that intermediary's process for verifying who is asking, not only on its firewalls.
We do not hold customer funds or customer identity documents — our company is a data and education service, described on the About page — but we teach how these systems work. The Crypto Academy covers what an exchange knows about you and why; our earlier article on Anthropic's threat intelligence report documented how impersonation is used at scale. Live, sourced market data — not personal data — is what we publish on Market Observation.
Sources
- TechCrunch, Jagmeet Singh, "Revolut confirms customer data breach through fake government requests", 12 September 2026, 7:40 AM PDT — Revolut's statement quoted verbatim; data categories; "limited" number of customers; notifications.
- CoinDesk, Shaurya Malwa, "Bitcoin activity, passports exposed after Revolut falls for fake government request", 12 September 2026, 10:11 AM (updated 10:50 AM) — ZachXBT's Telegram statement; data categories including Bitcoin transaction and withdrawal records, occupations, IBANs.
- The Block, "Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov't domain", 12 September 2026.
- TheStreet, "Revolut leak ties Bitcoin wallets to home addresses", 12 September 2026.
Educational content. Not investment advice.
Continue on DAI
Explore Topics
Written by
DAI Research Desk
Content creator and writer sharing insights and stories.


