Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Revolut Hackers Begin Leaking Customer Passports and Selfies, Threaten Daily Dumps

The attackers exploited a legitimate government email domain to bypass Revolut’s security checks and obtain passports, selfies and Bitcoin transaction histories.

Written By Dishita Malvania
Published 47 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Close-up of the Revolut brand logo in black text on a light background

A threat actor claiming to hold sensitive customer files taken from digital bank Revolut has begun publishing identity documents and verification selfies on public channels, and has said it will release further material every day until the company pays. 

The posts, seen on X and Telegram on 13 September 2026, follow Revolut’s confirmation earlier in the week that it disclosed customer records after accepting fraudulent information requests sent from an email account hosted on a legitimate government agency domain.

The escalation extends a case that The Crypto Times reported on 12 September 2026, after customer notices began surfacing the previous evening. Former Mt. Gox chief executive Mark Karpelès and on-chain investigator ZachXBT made the notices public, and several named users have since said publicly that they received the warnings.

AI Summary
Show
Revolut’s data leak could spur regulatory scrutiny, potentially delaying its US banking charter approval and affecting stock valuation.
Exposure of Bitcoin transaction histories may increase fraud risk, prompting tighter KYC controls across crypto platforms.
Threat actor’s ransom demands and ongoing leaks could raise compliance costs, pressuring Revolut’s profit margins and investor confidence.

What Revolut Has Confirmed

Revolut told Reuters and other outlets that it identified a “sophisticated external impersonation scam” in which an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information. A company spokesperson said Revolut blocked the address after detection, alerted the relevant government agency, law enforcement, data protection authorities and financial regulators, and contacted the “limited” number of impacted customers directly. The firm said its systems and customer funds were unaffected.

Revolut has not published the number of customers involved, the markets affected, or the name of the government agency whose domain was used.

Customer notices, excerpts of which Karpelès posted publicly on 12 September 2026, described the request as originating from an unauthorised mailbox that sat inside official government domain infrastructure and carried valid domain authentication. 

Because the messages passed standard email authentication checks, including Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC), Revolut treated them as genuine legal requests and released the files. Karpelès said he received a notice with the subject line “Urgent security update about your Revolut account” at 21:59 Coordinated Universal Time (UTC) on 11 September 2026.

Data Categories Listed in the Notices

Matching notice language across independent posts lists four groups of material that may have been disclosed.

The first covers identity details, including full name, date of birth and occupation. The second covers contact information, including postal address, email address and telephone number. The third covers document and verification data, meaning a copy of an identity document such as a passport or driving licence together with the facial verification image submitted at onboarding. 

Revolut has said no biometric facial telemetry data was involved, drawing a distinction between the selfie photograph itself, which is treated as disclosed, and the derived face template used for matching, which it says was not.

The fourth category covers financial records, including account statements with International Bank Account Number (IBAN), account status, opening date and wallet reference number, withdrawal records, and full transaction histories, including Bitcoin activity recorded through Revolut’s main app and its dedicated crypto trading platform Revolut X. 

Notices and company comments have not indicated that login passwords, card personal identification numbers (PINs), private keys or account balances were taken, and no stolen funds have been reported.

The Escalation and Named Individuals

On 13 September 2026, threat-intelligence account International Cyber Digest reported that the same threat actors had begun publishing sensitive customer data, including material they attributed to tennis player Alexander Shevchenko and Felix Römer, chief executive of online crypto casino Gamdom and Skinscom. 

The post said the actors want Revolut to pay, intend to release more messages, data and commentary on how Revolut’s team operates, and accuse the company of handing information to countries outside its jurisdiction and of negligence around privacy. Römer replied to the post on X, writing: “Ah wtf @Revolut.”

Dark-web monitoring account DailyDarkWeb posted on 13 September 2026 that the threat actor said: “We’re gonna start releasing more and more data everyday until Revolut pays for leaking their customers.” 

The same account noted that the identity of the attacker, the ransom demand, the claimed high-profile victims and the authenticity of the newly leaked material had not been independently confirmed by Revolut or law enforcement, and should be treated as threat-actor claims. No public, confirmed figure for the demanded payment has been issued by Revolut, and isolated social-media mentions of a large bitcoin demand have not been corroborated.

How the Fraudulent Request Cleared Controls

The mechanism is the part of the case that banks, exchanges and other Know Your Customer (KYC) heavy platforms are likely to study closely. The attacker did not need to breach Revolut production systems. The mailbox sat on a real government domain, and the messages carried valid SPF, DKIM and DMARC results. 

Revolut’s process treated domain authentication as evidence that the request itself was lawful. Revolut has not said whether the mailbox was hijacked from outside the agency, created internally without authority, or obtained by some other route.

Security site Help Net Security noted on 14 September 2026 that the case shifts the risk model from a conventional production-network breach to an attack on the trust path used for lawful disclosure, and that independent, out-of-band verification of sensitive government requests becomes essential when the payload is identity documents, KYC images or complete financial histories.

Why the Bitcoin Records Matter

Revolut records Bitcoin activity for customers who buy, sell, or withdraw through its main app and Revolut X. Pairing a full transaction history and an internal wallet reference number with a passport image, a verification selfie, an IBAN, and a residential address produces a dossier that is more useful for targeted fraud than a typical email-and-password dump. 

Address rotation on-chain does not undo that combination once the identity pack is public. A holder can rotate addresses but cannot rotate a passport photograph or a legal name.

Quinten van Welzen, Head of Marketing and Growth at Zano, a privacy-focused blockchain project, shared this comment exclusively with The Crypto Times. He said the residual risk sits with the on-chain link even if a dump campaign later stops: 

“The leak might be over, but the exposure isn’t. On transparent blockchains, once an address is linked to a person, the attacker can continue to monitor the transactions indefinitely. Moving funds to a private blockchain makes it harder for the attacker to learn about the crypto holder’s future transactions, but unfortunately it doesn’t erase the history that was already exposed.”

He added, “Blockchains can’t prevent companies from leaking user data, but privacy-preserving techniques limit what information an attacker can access. Financial privacy is a basic requirement for personal security. Revealing to the world that you’re in possession of a lot of cryptocurrency could leave you subject to extortion and wrench attacks.”

What Remains Unverified

The name of the government agency, the number of affected customers, the date range over which fraudulent requests were fulfilled, the method by which the mailbox was obtained, the authenticity of the 13 September dumps and any confirmed ransom terms all remain unresolved.

Revolut is separately in the middle of a broader expansion track that The Crypto Times has covered, including conditional approval from the Office of the Comptroller of the Currency for a United States national bank charter, the delisting of Tether’s USDT stablecoin under the European Union’s Markets in Crypto-Assets regime and the launch of the euro-backed EURR stablecoin. Those corporate milestones do not change the facts of the disclosure. They do raise the compliance cost if the leak campaign continues and if fresh files keep authenticating.

Guidance for Customers Who Received a Notice

Customers who received Revolut’s 11 to 12 September notice should treat the listed data classes as exposed for practical purposes, even while the authenticity of later Telegram dumps remains unverified. 

Users should watch for phishing messages that cite the incident, quote transaction history, or attach files that look like Revolut or government correspondence, and refuse to send documents or funds to anyone claiming to “secure” the leak. Revolut has said it is applying precautionary protections to affected accounts and has told customers to use official app and website channels only.

This is a developing incident. The confirmed core is narrow and serious. Revolut honoured a government-styled request that was not genuine, and the payload included KYC documents, selfies, and Bitcoin transaction histories for a limited customer set. The daily-leak campaign is a threat-actor claim now being tested in public. Until Revolut or law enforcement authenticates the new files and any payment demand, those elements should be reported as claims, not as settled fact.

Also Read: Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit, Offers Attacker 20% Bounty

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Hand holding a smartphone displaying the Binance app in front of the New York Stock Exchange
Binance Pitches AI Agents as a New Class of Crypto Exchange Customer
The U.S. Capitol Building with an American flag flying in front
US House Panel to Review Two Crypto Tax Bills on Sept. 16
Financial Conduct Authority FCA logo mounted on a white wall
FCA Explores New Rules for Tokenized Gold in UK Markets
Glowing orange-and-red neon Bitcoin token standing vertically against a dark background with an ascending financial candlestick chart
Bitcoin Holds Near $78K as Bottom Signals Fade Ahead of Fed Week
South Korean flag waving against a backdrop of modern glass financial skyscrapers
South Korea’s Opposition Party Rejects CBDC Until Safeguards Are in Place

Find Us on Socials

You may also like

Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit, Offers Attacker 20% Bounty

Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit, Offers Attacker 20% Bounty

Chainflip Halts Network After $736K Tron USDT Exploit; Users to Be Made Whole

Chainflip Halts Network After $736K Tron USDT Exploit; Users to Be Made Whole

Optim Finance Pauses OADA After Splash Pool Exploit Drains Cardano Liquidity

Optim Finance Pauses OADA After Splash Pool Exploit Drains Cardano Liquidity

Grayscale Files SEC Amendment to Convert Litecoin Trust Into NYSE Arca ETF

Grayscale Files SEC Amendment to Convert Litecoin Trust Into NYSE Arca ETF

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information