← Blog

Revolut Breach: Fake Gov Email Leaked KYC & BTC Data

Share on X

Revolut emailed customers after it handed over sensitive account files to someone who should never have received them. The request looked like it came from a real government agency — because it was sent from that agency’s official email domain, with authentication that checked out — and Revolut treated it as genuine. The notice that followed, first surfaced publicly by on-chain investigator ZachXBT and reported by crypto.news on September 12, 2026, says customers’ identities, KYC documents, and full transaction histories — including Bitcoin activity — may have been disclosed.

That is a Revolut data breach in the GDPR sense: personal data left the company under false pretenses. It is not a story about attackers rooting a production database or draining wallets. No private keys, passwords, or full card numbers appear in the categories Revolut listed. The damage is subtler and, for anyone who holds crypto on or through the app, still serious.

Alert emails went out around Friday, September 11, 2026. Revolut has not published a headcount. ZachXBT said the incident looked limited and appeared aimed at higher-net-worth users. Treat that as investigator commentary, not a company census.

What happened

According to the customer notice, an unauthorized sender used an official government agency’s email domain. The message carried valid domain authentication credentials. Revolut fulfilled the request “under the reasonable belief that it was an authentic government agency request.”

That matters. This was not a lookalike domain with a swapped letter, and it was not a PDF attachment with a fake letterhead. The email came from the real domain. SPF, DKIM, or whichever stack Revolut’s process trusted, cleared it. Someone had enough access — compromised mailbox, misused forwarding rule, insider help, or another path the notice does not describe — to send from that agency’s infrastructure.

The notice does not name the agency. It does not say when the request arrived or when Revolut first realized the sender was unauthorized. It does not claim Revolut’s own networks were breached, that customer logins were taken over, or that funds moved. The failure mode is process: a lawful-disclosure channel answered the wrong person.

If you received the September notice, assume the listed categories for your account may have left Revolut. If you did not, do not assume you are in the clear forever — but also do not invent membership in a list Revolut has not published.

What data was exposed

Revolut’s notice walks through categories that “may have been disclosed.” Not every field exists for every customer, and not every affected person necessarily had every category on file. The list is still brutal in combination.

Identity and contact fields included full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers.

Verification material included copies of identity documents — passports or driver’s licences — and the selfie images customers uploaded for identity checks. Revolut said biometric facial telemetry was not involved. That distinction matters for some risk models, but a passport scan plus a selfie is still a gift for fraudsters who want to open accounts elsewhere or craft convincing phishing.

Account and payment context included IBANs, account status, account-opening dates, withdrawal records, and full transaction histories. For crypto users, the notice explicitly mentions Bitcoin wallet reference numbers and Bitcoin transaction histories sitting alongside those bank-style fields.

What the notice does not put on the list: wallet private keys, account passwords, or full payment-card details. That is the line between “someone can impersonate and socially engineer you” and “someone can empty a hot wallet from the dump alone.” The first outcome is bad enough.

What this is not

To be clear: this is not the July 2026 dark-web claim that ~75 million Revolut records were for sale. Revolut disputed that listing; researchers could not validate the census. Our catalog keeps that row as an unverified claim. The September incident is a different path — a company notice about an unauthorized disclosure — and should not be mashed into the 75M story.

It is also not the 2022 Revolut incident in which social engineering against internal systems exposed personal data for tens of thousands of customers (widely reported around the 50,000 mark). Same brand, different year, different mechanism.

And it is not evidence that Bitcoin private keys leaked from Revolut. Wallet references and transaction histories are still sensitive. They map spending patterns, counterparties, and balances over time once you join them to a real name and an ID document.

How the attack worked

Call it what it is: social engineering of a financial institution’s government-request workflow, using a compromised or misused official domain rather than a spoofed lookalike.

Banks and fintechs routinely receive lawful requests from tax authorities, police, and financial-intelligence units. Those channels exist because regulation demands them. Attackers know that. If they can speak from a domain the recipient already trusts, they skip the hardest part of the con — getting past the “is this even a real agency?” filter.

Revolut’s notice frames the decision as reasonable belief based on authentication. That is both an explanation and a warning to every other firm that still treats “passes DMARC” as “must be the government.” Domain authentication proves the message was authorized by whoever controls that domain’s mail path. It does not prove the human behind the keyboard had a lawful warrant, a correct case file, or any right to the customer’s passport scan.

The missing pieces in public reporting are the ones security teams will care about most: which agency, how the mailbox was abused, whether Revolut used out-of-band verification (phone callback on a known number, portal pickup, dual control), and how quickly the company stopped fulfilling similar requests once it smelled smoke. Those answers were not in the screenshot ZachXBT shared.

Who is at risk

Anyone who received Revolut’s alert is in the primary blast radius. For those customers, assume identity documents and transaction detail may now sit with an unknown third party.

Crypto-active Revolut users carry an extra layer. A dump that pairs legal name, address, and ID images with Bitcoin transaction history is a roadmap for targeted phishing, SIM-swap attempts, and physical-security pressure. ZachXBT’s high-net-worth targeting note fits that pattern, even though Revolut has not confirmed selection criteria.

Customers who never got a notice are not automatically safe from secondary fraud. Scammers will still send “Revolut security / government request / verify your KYC” messages to people who were never in the file. The brand is loud enough that opportunistic phishing does not need a perfect victim list.

Family members and housemates can get collateral noise if a postal address or phone number was included and attackers start calling the household.

Concrete fraud patterns to expect

Once a fraudster has your legal name, home address, phone, email, and a copy of your passport or licence, the script writes itself. A caller claims to be Revolut fraud operations, quotes three true details from your file, and asks you to “secure” funds by moving them to a temporary account. A text message warns that a government agency has frozen crypto withdrawals and includes a link that looks like Revolut’s login. An email cites a Bitcoin wallet reference that actually appears in your history and demands you “confirm” a recovery seed so compliance can release the hold.

None of those plays require the attacker to have drained Revolut’s servers. They only need the disclosure packet and enough confidence to sound like they already know you. That is why pairing KYC images with transaction histories is so nasty for crypto users. On-chain data is often public in the abstract; it becomes personal the moment it is stapled to a selfie holding your passport.

Physical security deserves a mention even if it feels dramatic. Address disclosure plus wealth signalling — large transfers, frequent BTC moves, premium plan cues if any appeared in statements — is the same cocktail that has driven wrench attacks and home-visit threats in other crypto cases. Most victims will never face that. The ones who might are exactly the high-net-worth cohort ZachXBT flagged as a possible focus.

Industry context

Fintechs and exchanges live at the intersection of KYC retention and crypto transparency. They must store identity documents to satisfy AML rules. They also process on-chain or crypto-adjacent activity that becomes dangerous the moment it is glued to a passport. When those two datasets leave the building together, the privacy failure is worse than either alone.

Similar themes showed up in other 2026 incidents our catalog tracks: hardware-wallet brands hit via shipping and email vendors, remittance and banking apps listed in unverified dumps, and social-engineering campaigns that bypass technical controls by abusing trusted business processes. Revolut’s case is unusual because the trusted channel was a government-looking mailbox that authenticated correctly — a reminder that “verify the domain” is necessary and still insufficient.

Regulators already expect firms to assess personal data breaches for identity-theft and fraud risk. The UK Information Commissioner’s Office’s public guidance on personal data breaches stresses harm assessment, timely individual notice when risk is high, and, where required, regulator notification on short timelines. The customer screenshot does not say whether Revolut has filed with a supervisory authority or when the company first became aware of the fake request.

For other banks and fintechs reading this as a case study, the uncomfortable lesson is procedural. Out-of-band verification for government data requests — calling a published switchboard number, requiring pickup through a known law-enforcement portal, dual control between legal and fraud teams, watermarked production with audit logs — exists precisely because email authentication is not a warrant. Firms that still auto-trust any mail that clears DMARC on a .gov or agency domain are one compromised mailbox away from the same customer letter.

Comparisons help without inventing sameness. Vendor breaches at shipping and marketing providers (Trezor’s ShipMonk and Brevo incidents in the same season) show how third parties become the weak hinge. Revolut’s September notice is the mirror image: the hinge was a trusted inbound legal channel. Different door, same result for the customer — sensitive files in the wrong hands.

Timeline of what is public

Public reporting does not yet give a clean request date. What we can pin down:

  • Request and disclosure: Undated in the customer notice excerpt. Revolut fulfilled a message from an unauthorized account on an official government agency domain after authentication checks passed.
  • Customer alerts: Multiple customers reported receiving Revolut’s notice email on Friday, September 11, 2026, per ZachXBT.
  • Public amplification: September 12, 2026 — crypto.news published a detailed write-up from the notice screenshot; Coin Bureau and other market accounts circulated an alert framed around a fake government request.
  • Still unknown: Agency name, how domain mail access was obtained, internal discovery clock, regulator filings, and affected-user count.

That thin timeline is why responsible coverage has to stay disciplined. “Revolut got hacked and 80 million customers are toast” is not what the notice says. “Revolut answered a fake government-domain request and told some customers their KYC and transaction files may have gone out” is.

What Revolut and investigators said

Revolut’s notice, as quoted by crypto.news, states that the communication carried valid domain authentication credentials and was fulfilled under the belief it was authentic. It lists the data categories above and draws the line on biometric telemetry, passwords, private keys, and full card data.

ZachXBT posted the notice on Telegram, said multiple customers got alert mail on September 11, and characterized the incident as likely limited and possibly focused on wealthy users. Secondary coverage from Coin Bureau and crypto market wires amplified the same core facts on September 12.

As of indexing, Revolut had not published a named agency, a confirmed victim count, or a detailed timeline of request versus discovery. Absence of those details is not proof the incident was tiny — only that the public packet is incomplete.

Customers who want a paper trail should keep the original notice, note the date they received it, and ask Revolut in-app which categories applied to their account if the email is vague. If you are a journalist or researcher, the durable primary artifact remains the customer notice text — not social posts that compress it into “Revolut hacked.”

What you should do

  1. Read any Revolut email or in-app notice carefully. Confirm it inside the Revolut app support chat before you click links from your inbox. Revolut’s own security guidance says to verify suspicious contacts in-app and that it will not ask you for verification codes over the phone.
  2. Assume KYC documents may be in hostile hands if you were notified. Watch for new credit accounts, SIM-swap attempts, and tax or “government” phishing that cites your real address or ID number.
  3. Freeze or monitor credit where you live. In the UK, use formal credit-file tools and report suspected identity fraud to Action Fraud as appropriate. In the US, consider credit freezes at the major bureaus.
  4. Rotate Revolut credentials and enable the strongest MFA you can. Passwords were not listed as disclosed, but phishing against notified victims will try to obtain them anyway.
  5. Treat Bitcoin history as public-facing once linked to your name. Be wary of anyone who contacts you with oddly specific knowledge of your transfers, counterparties, or wallet references.
  6. Do not send seed phrases, recovery backups, or remote-access sessions to anyone claiming to be Revolut, police, or a tax agency. That pattern is how crypto theft actually finishes the job after a data disclosure.
  7. Keep the notice. If regulators or class counsel later seek victims, the dated email is evidence you were in scope.
  8. Report suspicious follow-up mail to Revolut in-app and, if it impersonates a government office, to the relevant fraud reporting channel in your country.

Canonical record and sources

BreachHistory catalog entry: https://breachhistory.com/revolut/revolut-fake-gov-request2026 (relative path /revolut/revolut-fake-gov-request2026). Distinct from the unverified 75M sale claim and the older 2022 Revolut incident.

Primary reporting: crypto.news — Revolut exposed Bitcoin records after fake agency request. Customer notice circulated via ZachXBT’s Telegram; September 11–12, 2026 coverage window. ICO personal-data-breach guidance and Revolut’s public security-help pages provide the regulatory and customer-response context cited above.

If Revolut later publishes an agency name, a regulator filing, or a confirmed headcount, the catalog row should be updated. Until then, the verified core is narrow and ugly: a fintech answered a government-domain email that was not a lawful request, and customers’ identity packs plus transaction — including Bitcoin — detail may have gone with it.