Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email

Revolut’s fake government request passed SPF, DKIM and DMARC checks before exposing customer KYC records and Bitcoin transaction histories.

Written By Dishita Malvania
Published 2 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email

British fintech Revolut has informed a subset of its customers that some of their personal and financial records, including Bitcoin transaction histories, were sent to an unauthorized third party after the firm treated a government-styled information request as genuine. 

The customer notice, which began circulating on September 11, 2026, described the request as originating from a mailbox that operated directly within an official government agency’s domain infrastructure and carried valid domain authentication credentials.

The story widened publicly on September 12, 2026, when former Mt. Gox Chief Executive Officer (CEO) Mark Karpelès posted substantial excerpts of the customer notice at 07:06 UTC, and after on-chain investigator ZachXBT flagged the case on his Telegram channel. 

Revolut customers were targeted in a fraudulent emergency data request sent via an email at a "government agency." https://t.co/sS2sbwAt8r

— Mark Karpelès (@MagicalTux) September 12, 2026

As of 09:13 Coordinated Universal Time (UTC) on September 12, Revolut had not issued a numbered press statement or a post from its main @Revolut account. The @revolutsupport account replied to a user at 06:42 UTC, saying “We take data protection and privacy concerns very seriously,” without adding facts beyond the customer email.

AI Summary
Show
Revolut’s data breach exposed Bitcoin transaction histories, potentially raising compliance costs and prompting investor scrutiny.
Targeted high‑net‑worth users could trigger larger insurance claims and affect Revolut’s risk‑weighting in financial markets.
Regulatory notifications may lead to fines and heightened oversight, pressuring Revolut’s stock valuation and market confidence.

What the Customer Notice Says

According to the notice quoted in excerpts by Karpelès, Revolut “received a request for information disguised as a legitimate government agency request.” The message stated that the request “originated from an unauthorized email account created directly within an official government authority’s domain infrastructure” and “carried genuine domain authentication credentials,” which led the firm to fulfil it “under the reasonable belief that it was an authentic government agency request.”

The customer email told recipients that Revolut later contacted the agency to verify the request and, in doing so, alerted that authority to the presence of an unauthorized account on its domain. After confirming the compromise, Revolut said it blocked the address across internal systems, notified relevant regulators, and applied “precautionary protection measures” for affected customers.

Karpelès, who identified himself as a recipient, said he received the email with the subject line “Urgent security update about your Revolut account” at 21:59 UTC on September 11. His earlier public inquiry directed at the company was posted at 21:05 UTC on the same day, asking whether the reported data leak was authentic.

The Data Categories Listed by Revolut

The notice, as quoted in Karpelès’s post, groups the possible disclosure into four categories.

Identity details include full name, date of birth, and occupation. Contact information covers postal address, email address, and telephone number. Document and verification data includes a copy of the identity document, such as a passport or driver’s licence, along with the facial verification image submitted at onboarding. 

The notice adds that “no biometric facial telemetry data was involved or compromised,” drawing a distinction between the selfie image itself and the derived biometric data used to authenticate a face.

The financial records described in the notice include account statements with the IBAN, account status, opening date, and wallet reference number, along with withdrawal records and full transaction history, including Bitcoin. The IBAN is the standard identifier for a customer’s bank account in Europe and several other regions. A wallet reference number is an internal identifier that maps a customer to their in-app crypto activity.

The notice does not describe wallet private keys, login passwords, card personal identification numbers (PINs), or account balances as being taken, and no report of stolen customer funds has emerged in public tracking of the story.

ZachXBT Flags the Incident, Says He Was Blocked

The disclosure gained wider visibility after pseudonymous on-chain investigator ZachXBT posted the case to his Telegram channel Investigations. In coverage attributed to that channel, he described the incident as likely limited in size and stated it “seems to have been targeted at high net worth users.”

On the morning of September 12, ZachXBT posted a set of screenshots at 06:51 UTC indicating that he had been blocked by both @Revolut and @revolutsupport on X. 

Idk why I am blocked by both Revolut accounts. pic.twitter.com/wLd3IdmSF9

— ZachXBT (@zachxbt) September 12, 2026

A follow-up post at 07:18 UTC said he had visited the accounts to check whether Revolut had posted about the incident and then found the blocks. Those posts do not add new facts about the data set itself, but they document how the story circulated within crypto research communities.

ZachXBT is the same investigator whose recent work The Crypto Times covered in the $667,000 French robbery laundering trace tied to the M1llionz handle, and the $5 million support-impersonation investigation implicating a United States-based operator earlier in August 2026.

Why the Bitcoin Records Matter

Revolut records identified Bitcoin activity for customers who buy, sell, or withdraw through its app and its separate crypto venue, Revolut X. Pairing a full transaction history and wallet reference number with a passport image, verification selfie, IBAN, and residential address produces a richer package than a typical email-and-password leak. Such a combination can support targeted phishing, account-recovery social engineering, and chain analysis that begins from a legal name rather than from an unnamed cluster.

That risk exists even though no coins have been reported moved on September 11 or 12. It also sits alongside a broader pattern of attackers exploiting trusted channels rather than protocol-level exploits. On September 9, 2026, Trezor said a compromised Brevo newsletter account was used to send a fake “Critical Security Alert: STM32 Entropy Vulnerability” to approximately 347,000 subscribers. That case affected only opt-in newsletter addresses and did not involve Know Your Customer (KYC) files, whereas the Revolut notice describes a legal-request process that trusted domain authentication without out-of-band verification.

How the Fake Request Reached Revolut

Financial institutions such as Revolut receive government requests for customer information regularly, in the form of law enforcement inquiries, court orders, and regulatory demands, and internal teams are built to comply with those when properly verified. 

The customer notice describes a mechanism in which a fraudulent request slipped through that verification layer because the mailbox sat within the agency’s actual domain and passed the sender authentication protocols used to detect spoofed email, namely Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC).

The notice does not describe an intrusion into Revolut’s production systems, an unauthorized login into a customer account, or the withdrawal of any funds. Karpelès argued that Revolut or the impersonated authority should identify the government body publicly so that other banks and exchanges can search their own legal-request logs for messages received from the same mailbox. No such identification has been published.

What Is Confirmed, and What Is Not

Confirmed by matching the notice text across independent posts, the incident involves the following facts: Revolut accepted an information request that appeared to originate from a government agency, the sending mailbox operated on that agency’s domain and passed domain authentication, Revolut later treated the mailbox as unauthorized and blocked it internally, and the firm notified regulators and emailed affected customers. 

The listed data categories include KYC images and Bitcoin transaction histories. Selfie images were included, while derived biometric telemetry was not, according to the notice.

As of 09:13 UTC on September 12, 2026, several elements remained unconfirmed. Revolut has not disclosed the exact number of customers included in the response, the country or name of the impersonated agency, the date on which the files left the firm, whether other financial institutions received the same mailbox, whether the third party has since reused the information, or whether a public statement from the main account will follow.

Earlier Revolut Incidents Are Separate Matters

This disclosure should not be conflated with prior events involving the firm. In September 2022, Lithuania’s State Data Protection Inspectorate recorded that 50,150 Revolut customers were affected after a social engineering attack against staff, in a case that used a different method four years earlier. 

In July 2026, a cybercrime forum listing claimed 75 million Revolut records were for sale, which the company disputed after an internal review, telling researchers that it believed the set was likely fabricated. 

In February 2026, Revolut confirmed that it had reported a former employee to law enforcement over an alleged ransom threat involving KYC data, with the company saying its systems operated as intended in that matter.

An unrelated operational issue was covered by The Crypto Times in May 2026, when Revolut blamed a third-party data provider for briefly displaying Bitcoin at near-zero prices in its app. None of these earlier matters is direct evidence for the September 2026 disclosure.

Guidance for Affected Customers

Revolut’s public fraud guidance directs customers to use the in-app chat feature rather than clicking links in unsolicited emails or answering unexpected calls. Customers who received the September 11 notice should treat unexpected messages or calls that cite the leak as high risk, because the exposed records contain the exact identity documents and account details used in customer verification and account-recovery workflows.

Naming the impersonated agency would allow other regulated platforms to search their own legal-request logs for messages received from the same mailbox. Until that identification is made, the primary documents in public view are the customer notice, the posts by Karpelès at 21:05 UTC and 07:06 UTC, the ZachXBT block screenshots, his follow-up citing his Telegram channel, and the Revolut Support reply at 06:42 UTC on September 12.

This is a developing story. The Crypto Times will update its coverage if Revolut names the impersonated agency, publishes a customer count, or if a regulator posts a filing.

Also Read: Trezor Confirms Phishing Attack After Email Provider Breach, Users Warned

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Coinbase CFO Says It Has SEC-CFTC Backup Plan if CLARITY Act Stalls
Coinbase CFO Says It Has SEC-CFTC Backup Plan if CLARITY Act Stalls
India’s FM Urges RBI to Scale Digital Rupee Pilots Amid Tokenisation Push
India’s FM Urges RBI to Scale Digital Rupee Pilots Amid Tokenisation Push
Wintermute Moves $160M in ETH to Binance and Coinbase as Ethereum Rejects $2,667
Wintermute Moves $160M in ETH to Binance and Coinbase as Ethereum Rejects $2,667
Central Bureau of Investigation India emblem mounted on a stone wall.
CBI Warns Indian Crypto Users Over P2P Trades and UPI Payments
Zentra Finance logo on a soft orange and white gradient background.
Zentra Finance Reports $143K Exploit Affecting ctUSD Reserve

Find Us on Socials

You may also like

Bitcoin Suisse logo mounted on a dark wall.

Bitcoin Suisse to Slash Up to 50% of Swiss Jobs in Major Offshore Shift

The Smarter Web Company logo mounted on a black wall.

Smarter Web Proposes Up to £25M Preferred Shares IPO in UK 

Smartphone displaying the UniCredit logo against a red and white background.

Italian Bank UniCredit Plans Digital Asset Custody and Brokerage Infrastructure

Blockaid and Atomic Digital logos displayed on blue glass blocks side by side.

Atomic Digital Deploys Blockaid’s Onchain Monitoring Across DeFi Portfolio 

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information