British fintech Revolut has informed a subset of its customers that some of their personal and financial records, including Bitcoin transaction histories, were sent to an unauthorized third party after the firm treated a government-styled information request as genuine.
The customer notice, which began circulating on September 11, 2026, described the request as originating from a mailbox that operated directly within an official government agency’s domain infrastructure and carried valid domain authentication credentials.
The story widened publicly on September 12, 2026, when former Mt. Gox Chief Executive Officer (CEO) Mark Karpelès posted substantial excerpts of the customer notice at 07:06 UTC, and after on-chain investigator ZachXBT flagged the case on his Telegram channel.
As of 09:13 Coordinated Universal Time (UTC) on September 12, Revolut had not issued a numbered press statement or a post from its main @Revolut account. The @revolutsupport account replied to a user at 06:42 UTC, saying “We take data protection and privacy concerns very seriously,” without adding facts beyond the customer email.
What the Customer Notice Says
According to the notice quoted in excerpts by Karpelès, Revolut “received a request for information disguised as a legitimate government agency request.” The message stated that the request “originated from an unauthorized email account created directly within an official government authority’s domain infrastructure” and “carried genuine domain authentication credentials,” which led the firm to fulfil it “under the reasonable belief that it was an authentic government agency request.”
The customer email told recipients that Revolut later contacted the agency to verify the request and, in doing so, alerted that authority to the presence of an unauthorized account on its domain. After confirming the compromise, Revolut said it blocked the address across internal systems, notified relevant regulators, and applied “precautionary protection measures” for affected customers.
Karpelès, who identified himself as a recipient, said he received the email with the subject line “Urgent security update about your Revolut account” at 21:59 UTC on September 11. His earlier public inquiry directed at the company was posted at 21:05 UTC on the same day, asking whether the reported data leak was authentic.
The Data Categories Listed by Revolut
The notice, as quoted in Karpelès’s post, groups the possible disclosure into four categories.
Identity details include full name, date of birth, and occupation. Contact information covers postal address, email address, and telephone number. Document and verification data includes a copy of the identity document, such as a passport or driver’s licence, along with the facial verification image submitted at onboarding.
The notice adds that “no biometric facial telemetry data was involved or compromised,” drawing a distinction between the selfie image itself and the derived biometric data used to authenticate a face.
The financial records described in the notice include account statements with the IBAN, account status, opening date, and wallet reference number, along with withdrawal records and full transaction history, including Bitcoin. The IBAN is the standard identifier for a customer’s bank account in Europe and several other regions. A wallet reference number is an internal identifier that maps a customer to their in-app crypto activity.
The notice does not describe wallet private keys, login passwords, card personal identification numbers (PINs), or account balances as being taken, and no report of stolen customer funds has emerged in public tracking of the story.
ZachXBT Flags the Incident, Says He Was Blocked
The disclosure gained wider visibility after pseudonymous on-chain investigator ZachXBT posted the case to his Telegram channel Investigations. In coverage attributed to that channel, he described the incident as likely limited in size and stated it “seems to have been targeted at high net worth users.”
On the morning of September 12, ZachXBT posted a set of screenshots at 06:51 UTC indicating that he had been blocked by both @Revolut and @revolutsupport on X.
A follow-up post at 07:18 UTC said he had visited the accounts to check whether Revolut had posted about the incident and then found the blocks. Those posts do not add new facts about the data set itself, but they document how the story circulated within crypto research communities.
ZachXBT is the same investigator whose recent work The Crypto Times covered in the $667,000 French robbery laundering trace tied to the M1llionz handle, and the $5 million support-impersonation investigation implicating a United States-based operator earlier in August 2026.
Why the Bitcoin Records Matter
Revolut records identified Bitcoin activity for customers who buy, sell, or withdraw through its app and its separate crypto venue, Revolut X. Pairing a full transaction history and wallet reference number with a passport image, verification selfie, IBAN, and residential address produces a richer package than a typical email-and-password leak. Such a combination can support targeted phishing, account-recovery social engineering, and chain analysis that begins from a legal name rather than from an unnamed cluster.
That risk exists even though no coins have been reported moved on September 11 or 12. It also sits alongside a broader pattern of attackers exploiting trusted channels rather than protocol-level exploits. On September 9, 2026, Trezor said a compromised Brevo newsletter account was used to send a fake “Critical Security Alert: STM32 Entropy Vulnerability” to approximately 347,000 subscribers. That case affected only opt-in newsletter addresses and did not involve Know Your Customer (KYC) files, whereas the Revolut notice describes a legal-request process that trusted domain authentication without out-of-band verification.
How the Fake Request Reached Revolut
Financial institutions such as Revolut receive government requests for customer information regularly, in the form of law enforcement inquiries, court orders, and regulatory demands, and internal teams are built to comply with those when properly verified.
The customer notice describes a mechanism in which a fraudulent request slipped through that verification layer because the mailbox sat within the agency’s actual domain and passed the sender authentication protocols used to detect spoofed email, namely Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC).
The notice does not describe an intrusion into Revolut’s production systems, an unauthorized login into a customer account, or the withdrawal of any funds. Karpelès argued that Revolut or the impersonated authority should identify the government body publicly so that other banks and exchanges can search their own legal-request logs for messages received from the same mailbox. No such identification has been published.
What Is Confirmed, and What Is Not
Confirmed by matching the notice text across independent posts, the incident involves the following facts: Revolut accepted an information request that appeared to originate from a government agency, the sending mailbox operated on that agency’s domain and passed domain authentication, Revolut later treated the mailbox as unauthorized and blocked it internally, and the firm notified regulators and emailed affected customers.
The listed data categories include KYC images and Bitcoin transaction histories. Selfie images were included, while derived biometric telemetry was not, according to the notice.
As of 09:13 UTC on September 12, 2026, several elements remained unconfirmed. Revolut has not disclosed the exact number of customers included in the response, the country or name of the impersonated agency, the date on which the files left the firm, whether other financial institutions received the same mailbox, whether the third party has since reused the information, or whether a public statement from the main account will follow.
Earlier Revolut Incidents Are Separate Matters
This disclosure should not be conflated with prior events involving the firm. In September 2022, Lithuania’s State Data Protection Inspectorate recorded that 50,150 Revolut customers were affected after a social engineering attack against staff, in a case that used a different method four years earlier.
In July 2026, a cybercrime forum listing claimed 75 million Revolut records were for sale, which the company disputed after an internal review, telling researchers that it believed the set was likely fabricated.
In February 2026, Revolut confirmed that it had reported a former employee to law enforcement over an alleged ransom threat involving KYC data, with the company saying its systems operated as intended in that matter.
An unrelated operational issue was covered by The Crypto Times in May 2026, when Revolut blamed a third-party data provider for briefly displaying Bitcoin at near-zero prices in its app. None of these earlier matters is direct evidence for the September 2026 disclosure.
Guidance for Affected Customers
Revolut’s public fraud guidance directs customers to use the in-app chat feature rather than clicking links in unsolicited emails or answering unexpected calls. Customers who received the September 11 notice should treat unexpected messages or calls that cite the leak as high risk, because the exposed records contain the exact identity documents and account details used in customer verification and account-recovery workflows.
Naming the impersonated agency would allow other regulated platforms to search their own legal-request logs for messages received from the same mailbox. Until that identification is made, the primary documents in public view are the customer notice, the posts by Karpelès at 21:05 UTC and 07:06 UTC, the ZachXBT block screenshots, his follow-up citing his Telegram channel, and the Revolut Support reply at 06:42 UTC on September 12.
This is a developing story. The Crypto Times will update its coverage if Revolut names the impersonated agency, publishes a customer count, or if a regulator posts a filing.
Also Read: Trezor Confirms Phishing Attack After Email Provider Breach, Users Warned
