Revolut informed a group of customers that their passports, personal addresses, and complete Bitcoin (BTC) transaction histories had been sent to an unauthorized third party, after a forged government request successfully passed its internal checks.
Key points:
Revolut shared identity documents and Bitcoin transaction histories after it mistakenly took a fraudulent request, presented as coming from the authorities, to be authentic.
The fintech says the funds are safe and that the regulators were notified, but it neither named the impersonated authority nor indicated the number of affected clients.
According to investigators, the leak appears limited in volume and would primarily target wealthy clients.
A Revolut notice highlights exposure to Bitcoin
The bank sent an email to the affected clients late in the evening of September 11. The on-chain investigator ZachXBT then reported this message on his Telegram channel a few hours later.
According to this notice, the data request came from an unauthorized account created within the official name domain of a government authority itself and containing real domain authentication information. Revolut handled the subpoena, deeming that it was “reasonable” for it to be authentic.
The disclosed information includes full names, dates of birth, professions, postal addresses, email addresses, phone numbers, passport or driver’s license copies, as well as the selfie taken when opening the account.
Account statements with IBAN, account opening dates, and portfolio references were also provided, along with complete withdrawal and transaction histories, including operations in Bitcoin.
Revolut then contacted the relevant authority to verify the request and, in doing so, alerted it to the existence of this unauthorized account hosted on its own domain. The company says its clients’ funds remain secure and that no passwords were compromised. Regulators were informed, but Revolut did not specify how many people were affected.
Also read: Ethereum hits a $2,800 supply wall as flows to ETFs jump by $216M
ZachXBT and Karpelès increase the pressure on Revolut
ZachXBT believes the incident is likely limited in size and appears to target high-net-worth clients. He then published screenshots showing that the two Revolut X accounts had blocked him after he checked whether the company had publicly communicated about the matter.
Mark Karpelès, former CEO of Mt. Gox, says he received the alert with the subject line “Urgent security update about your Revolut account” and shared long excerpts from it.
He calls on Revolut or the impersonated authority to publish the latter’s name, so that other banks and exchange platforms can verify their records of legal requests and look up this same email address. A Revolut support account replied, stating that the company takes confidentiality “very seriously.”
Bitcoin history that increases the risk of targeting
Public blockchains show the movement of tokens, but they contain neither passport scans nor profession nor postal address. Linking a verified identity to a comprehensive transaction history turns a simple compliance file into a real map of who holds what—and where those people sleep at night.
Revolut has already faced difficulties in protecting data. The Lithuanian data protection regulator had identified 50,150 Revolut clients affected by a social engineering attack targeting employees in September 2022. The company also challenged a post on a forum in July 2026 claiming that 75 million of its records were for sale, assuring researchers that this dataset was likely fabricated.
To follow: Jensen Huang of Nvidia claims that cybersecurity actors benefit from panic over threats related to AI
