British fintech Revolut has knowledgeable a subset of its clients that a few of their private and monetary information, together with Bitcoin transaction histories, have been despatched to an unauthorized third social gathering after the agency handled a government-styled info request as real.
The shopper discover, which started circulating on September 11, 2026, described the request as originating from a mailbox that operated immediately inside an official authorities company’s area infrastructure and carried legitimate area authentication credentials.
The story widened publicly on September 12, 2026, when former Mt. Gox Chief Govt Officer (CEO) Mark Karpelès posted substantial excerpts of the client discover at 07:06 UTC, and after on-chain investigator ZachXBT flagged the case on his Telegram channel.
As of 09:13 Coordinated Common Time (UTC) on September 12, Revolut had not issued a numbered press assertion or a publish from its principal @Revolut account. The @revolutsupport account replied to a consumer at 06:42 UTC, saying “We take information safety and privateness considerations very critically,” with out including details past the client e mail.
Revolut’s information breach uncovered Bitcoin transaction histories, probably elevating compliance prices and prompting investor scrutiny.
Focused excessive‑web‑price customers might set off bigger insurance coverage claims and have an effect on Revolut’s threat‑weighting in monetary markets.
Regulatory notifications could result in fines and heightened oversight, pressuring Revolut’s inventory valuation and market confidence.
What the Buyer Discover Says
In line with the discover quoted in excerpts by Karpelès, Revolut “obtained a request for info disguised as a authentic authorities company request.” The message acknowledged that the request “originated from an unauthorized e mail account created immediately inside an official authorities authority’s area infrastructure” and “carried real area authentication credentials,” which led the agency to fulfil it “underneath the cheap perception that it was an genuine authorities company request.”
The shopper e mail advised recipients that Revolut later contacted the company to confirm the request and, in doing so, alerted that authority to the presence of an unauthorized account on its area. After confirming the compromise, Revolut stated it blocked the deal with throughout inside techniques, notified related regulators, and utilized “precautionary safety measures” for affected clients.
Karpelès, who recognized himself as a recipient, said he obtained the e-mail with the topic line “Pressing safety replace about your Revolut account” at 21:59 UTC on September 11. His earlier public inquiry directed on the firm was posted at 21:05 UTC on the identical day, asking whether or not the reported information leak was genuine.
The Information Classes Listed by Revolut
The discover, as quoted in Karpelès’s publish, teams the doable disclosure into 4 classes.
Id particulars embrace full title, date of start, and occupation. Contact info covers postal deal with, e mail deal with, and phone quantity. Doc and verification information features a copy of the id doc, akin to a passport or driver’s licence, together with the facial verification picture submitted at onboarding.
The discover provides that “no biometric facial telemetry information was concerned or compromised,” drawing a distinction between the selfie picture itself and the derived biometric information used to authenticate a face.
The monetary information described within the discover embrace account statements with the IBAN, account standing, opening date, and pockets reference quantity, together with withdrawal information and full transaction historical past, together with Bitcoin. The IBAN is the usual identifier for a buyer’s checking account in Europe and several other different areas. A pockets reference quantity is an inside identifier that maps a buyer to their in-app crypto exercise.
The discover doesn’t describe pockets non-public keys, login passwords, card private identification numbers (PINs), or account balances as being taken, and no report of stolen buyer funds has emerged in public monitoring of the story.
ZachXBT Flags the Incident, Says He Was Blocked
The disclosure gained wider visibility after pseudonymous on-chain investigator ZachXBT posted the case to his Telegram channel Investigations. In protection attributed to that channel, he described the incident as possible restricted in measurement and acknowledged it “appears to have been focused at excessive web price customers.”
On the morning of September 12, ZachXBT posted a set of screenshots at 06:51 UTC indicating that he had been blocked by each @Revolut and @revolutsupport on X.
A follow-up post at 07:18 UTC stated he had visited the accounts to test whether or not Revolut had posted in regards to the incident after which discovered the blocks. These posts don’t add new details in regards to the information set itself, however they doc how the story circulated inside crypto analysis communities.
ZachXBT is similar investigator whose latest work The Crypto Instances lined within the $667,000 French robbery laundering trace tied to the M1llionz deal with, and the $5 million support-impersonation investigation implicating a United States-based operator earlier in August 2026.
Why the Bitcoin Information Matter
Revolut information recognized Bitcoin exercise for purchasers who purchase, promote, or withdraw by its app and its separate crypto venue, Revolut X. Pairing a full transaction historical past and pockets reference quantity with a passport picture, verification selfie, IBAN, and residential deal with produces a richer package deal than a typical email-and-password leak. Such a mix can assist focused phishing, account-recovery social engineering, and chain evaluation that begins from a authorized title moderately than from an unnamed cluster.
That threat exists although no cash have been reported moved on September 11 or 12. It additionally sits alongside a broader sample of attackers exploiting trusted channels moderately than protocol-level exploits. On September 9, 2026, Trezor said a compromised Brevo newsletter account was used to ship a faux “Essential Safety Alert: STM32 Entropy Vulnerability” to roughly 347,000 subscribers. That case affected solely opt-in e-newsletter addresses and didn’t contain Know Your Buyer (KYC) recordsdata, whereas the Revolut discover describes a legal-request course of that trusted area authentication with out out-of-band verification.
How the Pretend Request Reached Revolut
Monetary establishments akin to Revolut obtain authorities requests for buyer info repeatedly, within the type of regulation enforcement inquiries, courtroom orders, and regulatory calls for, and inside groups are constructed to adjust to these when correctly verified.
The shopper discover describes a mechanism wherein a fraudulent request slipped by that verification layer as a result of the mailbox sat inside the company’s precise area and handed the sender authentication protocols used to detect spoofed e mail, particularly Sender Coverage Framework (SPF), DomainKeys Recognized Mail (DKIM) and Area-based Message Authentication, Reporting and Conformance (DMARC).
The discover doesn’t describe an intrusion into Revolut’s manufacturing techniques, an unauthorized login right into a buyer account, or the withdrawal of any funds. Karpelès argued that Revolut or the impersonated authority ought to determine the federal government physique publicly in order that different banks and exchanges can search their very own legal-request logs for messages obtained from the identical mailbox. No such identification has been revealed.
What Is Confirmed, and What Is Not
Confirmed by matching the discover textual content throughout unbiased posts, the incident entails the next details: Revolut accepted an info request that appeared to originate from a authorities company, the sending mailbox operated on that company’s area and handed area authentication, Revolut later handled the mailbox as unauthorized and blocked it internally, and the agency notified regulators and emailed affected clients.
The listed information classes embrace KYC pictures and Bitcoin transaction histories. Selfie pictures have been included, whereas derived biometric telemetry was not, in line with the discover.
As of 09:13 UTC on September 12, 2026, a number of parts remained unconfirmed. Revolut has not disclosed the precise variety of clients included within the response, the nation or title of the impersonated company, the date on which the recordsdata left the agency, whether or not different monetary establishments obtained the identical mailbox, whether or not the third social gathering has since reused the knowledge, or whether or not a public assertion from the primary account will comply with.
Earlier Revolut Incidents Are Separate Issues
This disclosure shouldn’t be conflated with prior occasions involving the agency. In September 2022, Lithuania’s State Information Safety Inspectorate recorded that fifty,150 Revolut clients have been affected after a social engineering assault towards workers, in a case that used a distinct technique 4 years earlier.
In July 2026, a cybercrime discussion board itemizing claimed 75 million Revolut information have been on the market, which the corporate disputed after an inside evaluate, telling researchers that it believed the set was possible fabricated.
In February 2026, Revolut confirmed that it had reported a former worker to regulation enforcement over an alleged ransom risk involving KYC information, with the corporate saying its techniques operated as meant in that matter.
An unrelated operational difficulty was lined by The Crypto Instances in Might 2026, when Revolut blamed a third-party data provider for briefly displaying Bitcoin at near-zero costs in its app. None of those earlier issues is direct proof for the September 2026 disclosure.
Steering for Affected Prospects
Revolut’s public fraud steering directs clients to make use of the in-app chat function moderately than clicking hyperlinks in unsolicited emails or answering sudden calls. Prospects who obtained the September 11 discover ought to deal with sudden messages or calls that cite the leak as excessive threat, as a result of the uncovered information comprise the precise id paperwork and account particulars utilized in buyer verification and account-recovery workflows.
Naming the impersonated company would enable different regulated platforms to look their very own legal-request logs for messages obtained from the identical mailbox. Till that identification is made, the first paperwork in public view are the client discover, the posts by Karpelès at 21:05 UTC and 07:06 UTC, the ZachXBT block screenshots, his follow-up citing his Telegram channel, and the Revolut Assist reply at 06:42 UTC on September 12.
This can be a growing story. The Crypto Instances will replace its protection if Revolut names the impersonated company, publishes a buyer rely, or if a regulator posts a submitting.
Additionally Learn: Trezor Confirms Phishing Attack After Email Provider Breach, Users Warned
Disclaimer: The data researched and reported by The Crypto Instances is for informational functions solely and isn’t an alternative choice to skilled monetary recommendation. Investing in crypto belongings entails vital threat on account of market volatility. All the time Do Your Personal Analysis (DYOR) and seek the advice of with a certified Monetary Advisor earlier than making any funding choices.





