- Revolut disclosed information after receiving a fraudulent request from an unauthorized mailbox operating inside a genuine government agency domain.
- The exposed material may include identity documents, verification selfies, addresses, account statements and complete Bitcoin transaction histories.
- Revolut says it later verified that the request was unauthorized, blocked the address, alerted the agency and began notifying regulators.
- The company has not disclosed the affected agency, the number of customers involved or how the unauthorized mailbox was created.
Revolut disclosed personal and financial information belonging to some customers after treating a fraudulent government information request as legitimate, exposing a weakness in how lawful data demands are authenticated when the requesting authority’s own email infrastructure is compromised.
The request came from a real government domain
The incident differs from a conventional phishing attack because the malicious request was not simply sent from a lookalike email address.
According to excerpts from a security notice sent to affected customers, the request originated from an unauthorized email account created within the domain infrastructure of an official government authority. It also carried genuine domain authentication credentials.

That distinction is central to the case. Email controls such as SPF, DKIM and DMARC are designed to help recipients establish whether a message is authorized by the domain it claims to represent. In this case, those checks reportedly passed because the sender was operating from infrastructure associated with the government domain rather than merely impersonating it from outside.
Revolut said it fulfilled the request under the belief that it came from a legitimate government agency. The company later contacted the authority to verify it and concluded that the mailbox was unauthorized.
Revolut then blocked the address across its internal systems, alerted the agency to the unauthorized account and notified relevant regulators, according to the customer communication.
Passports, selfies and Bitcoin histories may have been disclosed
The potential exposure extends well beyond basic account information.
According to the notice, information provided to the unauthorized party may have included:
- Identity data: full name, date of birth and occupation
- Contact details: home address, email address and telephone number
- KYC records: copies of passports or driving licences and facial verification images submitted during onboarding
- Financial information: IBAN, account status, opening date, wallet reference numbers, withdrawal records, account statements and full transaction histories, including Bitcoin activity
Revolut said biometric facial telemetry was not compromised, distinguishing the verification image itself from biometric information derived from facial analysis.
There is currently no indication that passwords, card PINs or crypto private keys were included, and no public evidence that customer funds were stolen as part of the incident.
Bitcoin records make the exposure harder to contain
The inclusion of complete Bitcoin transaction histories changes the risk profile of the disclosure.
A leaked password can be replaced. A payment card can be cancelled. Historical records linking a person’s legal identity to crypto activity cannot be reset in the same way.
If the disclosed records connect a customer’s name, residential address and identity documents with Bitcoin transactions or identifiable wallet activity, an attacker could potentially build a much more detailed profile of that individual.
The combination is particularly useful for targeted social engineering. Someone already holding a passport image, selfie, telephone number, address and genuine transaction information can construct messages or calls that contain details a victim would normally expect only a financial institution or government authority to know.
It may also reduce the anonymity surrounding historical blockchain activity if disclosed records provide enough information to associate transactions with a known individual.
This is why the scope matters as much as the number of affected accounts. A relatively small breach containing highly concentrated identity and financial information can create a different risk from a much larger database containing only email addresses or passwords.
ZachXBT says high-net-worth users may have been targeted
The incident gained wider attention after on-chain investigator ZachXBT circulated information about the customer notices.
ZachXBT said the incident appeared to be limited in size and potentially targeted at high-net-worth users.
Idk why I am blocked by both Revolut accounts. pic.twitter.com/wLd3IdmSF9
— ZachXBT (@zachxbt) September 12, 2026
That assessment has not been confirmed by Revolut and should therefore be treated as his interpretation of the available evidence rather than an established fact.
Former Mt. Gox CEO Mark Karpelès also publicly shared substantial excerpts from a notice he said he received from Revolut on September 11, helping establish the contents of the customer communication.
As of September 12, Revolut’s public news page did not contain a dedicated announcement detailing the incident.
The authentication failure goes beyond spoofed email
The unresolved security issue is not whether Revolut could detect a misspelled government domain. The available account indicates that the email passed the technical checks normally used to establish that a message belongs to its stated domain.
That leaves a separate question: what additional verification is required before a financial institution releases sensitive customer records in response to an official request?
An out-of-band confirmation process, for example, would attempt to establish the legitimacy of the individual request through a channel independent of the originating mailbox. The incident suggests domain authentication alone cannot establish that the person controlling an authenticated government account is authorized to request the data.
That issue may extend beyond Revolut. If the unauthorized mailbox was capable of sending authenticated requests to one financial institution, identifying the government agency and the period during which the account was active could allow other banks, exchanges and payment companies to check whether they received requests from the same address.
Revolut has not publicly named the agency, explained how the mailbox was obtained or created, or disclosed how many customers were affected.
Those details now determine whether the incident remains a narrowly targeted disclosure or points to a broader weakness in the handling of authenticated government information requests.
Credit: Source link








