← Revolut

2026 Revolut — fake government-domain request; KYC + Bitcoin tx histories disclosed

2026 Unknown records affected Share on X

Data compromised

May have included full names, DOBs, occupations, postal addresses, emails, phones; ID document copies (passport/DL) and KYC selfies (biometric facial telemetry excluded per notice); IBANs, account status, opening dates, withdrawal records, full transaction histories including Bitcoin wallet reference numbers and Bitcoin transactions. Passwords, private keys, and full payment-card details not listed.

Technical writeup

Company-confirmed unauthorized disclosure — Revolut customer notice circulated September 11–12, 2026 (ZachXBT Telegram; crypto.news Sep 12). An unauthorized party sent a request from an official government agency email domain that passed domain authentication; Revolut fulfilled it under the belief it was authentic. Disclosed categories may include identity/contact data, ID document copies, KYC selfies (not biometric telemetry), IBANs/account metadata, withdrawal records, and full transaction histories including Bitcoin wallet references and Bitcoin transactions. Notice does not claim Revolut systems were intruded or funds withdrawn; does not name the agency or publish a victim census. Distinct from the unverified July 2026 ~75M sale claim and the 2022 ~50k social-engineering incident. recordsAffected 0 pending census; companyConfirmed true.

Root cause

Unauthorized sender used an official government agency email domain with valid authentication; Revolut fulfilled the request believing it was a genuine agency disclosure demand

References