2026 Revolut — fake government-domain request; KYC + Bitcoin tx histories disclosed
Data compromised
May have included full names, DOBs, occupations, postal addresses, emails, phones; ID document copies (passport/DL) and KYC selfies (biometric facial telemetry excluded per notice); IBANs, account status, opening dates, withdrawal records, full transaction histories including Bitcoin wallet reference numbers and Bitcoin transactions. Passwords, private keys, and full payment-card details not listed.
Technical writeup
Company-confirmed unauthorized disclosure — Revolut customer notice circulated September 11–12, 2026 (ZachXBT Telegram; crypto.news Sep 12). An unauthorized party sent a request from an official government agency email domain that passed domain authentication; Revolut fulfilled it under the belief it was authentic. Disclosed categories may include identity/contact data, ID document copies, KYC selfies (not biometric telemetry), IBANs/account metadata, withdrawal records, and full transaction histories including Bitcoin wallet references and Bitcoin transactions. Notice does not claim Revolut systems were intruded or funds withdrawn; does not name the agency or publish a victim census. Distinct from the unverified July 2026 ~75M sale claim and the 2022 ~50k social-engineering incident. recordsAffected 0 pending census; companyConfirmed true.
Root cause
Unauthorized sender used an official government agency email domain with valid authentication; Revolut fulfilled the request believing it was a genuine agency disclosure demand
References
- https://crypto.news/revolut-exposed-bitcoin-records-fake-agency-request/
- https://pluang.com/en/news-feed/revolut-bocorkan-data-bitcoin-karena-permintaan-palsu
- https://x.com/coinbureau/status/2098684872395301092
- https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/