Revolut reportedly disclosed customer identity and financial records, including Bitcoin transaction histories and wallet reference numbers, after responding to a fraudulent request that used an official government-agency email domain, according to secondary reporting that has not been independently authenticated.
Revolut reportedly disclosed customer identity and financial records, including Bitcoin transaction histories and wallet reference numbers, after responding to a fraudulent request that used an official government-agency email domain, according to secondary reporting that has not been independently authenticated. The reported Revolut Bitcoin activity exposure raises questions about request validation, not about any intrusion into the fintech’s systems.
What to Know
- The reporting links a fake agency request to the exposure of Bitcoin activity and other customer records held by Revolut.
- The available materials do not establish the full disclosure scope, the number of affected customers, or the incident’s impact.
What the Reporting Says About the Revolut Fake Request Incident
A September 12, 2026 report by Lawrence Mondal at crypto.news says Revolut sent customer identities and financial records in response to a fraudulent government-agency request, based on a reproduced customer notice. That report verifies the published account, not independent authentication of the underlying notice itself. For related coverage, see BTCPay Emergency Patch Exposes Merchant-Side Bitcoin Security Risk.
According to the notice as described by crypto.news, the requester used an unauthorized email account on an official government agency domain, and the message passed domain authentication checks. The report does not establish the technical method used to obtain or impersonate that account, leaving the core question of how the request was validated unresolved. For related coverage, see Bitcoin Long-Term Holders Sold 539,000 BTC: CryptoQuant.
The same reporting describes a separate pattern of reported KYC data and Bitcoin history exposure tied to Revolut, though a first-party copy of the customer notice was not fetched or authenticated in this research. Absent that primary document, the authenticity and completeness of the notice remain unconfirmed. For related coverage, see Revolut Receives Conditional OCC Approval for U.S. National Bank Charter.
What Bitcoin Activity and Personal Data Were Described as Exposed
The report lists full names, dates of birth, occupations, postal and email addresses, telephone numbers, identity-document copies and identity-verification selfies among the categories described in the notice. It says the notice distinguished those verification selfies from biometric facial telemetry, which it stated was not involved.
On the financial side, the report says account statements listed IBANs, account status, account-opening dates and Bitcoin wallet reference numbers, while withdrawal records and full transaction histories, including Bitcoin transactions, were also described as disclosed. These categories overlap with an earlier account of a breach exposing passports and Bitcoin records.
The reported categories do not establish that every affected customer had every category disclosed. Crucially, this is an information-disclosure event as described: the fetched evidence does not demonstrate theft of funds, exposure of private keys, or any intrusion into Revolut’s systems.
The scale also remains uncertain. crypto.news attributes to on-chain investigator ZachXBT the statement that multiple customers received alert emails on September 11, 2026, but reports no confirmed affected-customer count and says the notice provided no date for the request or the disclosure.
ZachXBT noted that the incident appeared limited in size and may have targeted high-net-worth users, according to crypto.news; the investigator’s assessment is available only through that attributed secondary reporting, and according to unconfirmed reports the reproduced notice does not itself confirm customer selection or scale.
Privacy Questions and What Regulators Require
The UK Information Commissioner’s Office defines a personal data breach to include unauthorized disclosure and sending personal data to an incorrect recipient, and its public breach guidance states that evidence of a network intrusion is not required to meet that definition. A misdirected disclosure can therefore qualify even without a system compromise.
Where UK GDPR applies, the ICO says a notifiable breach must be reported to the authority within 72 hours of awareness where feasible, and affected individuals must be informed without undue delay when a breach is likely to create a high risk to their rights and freedoms. Article 33(4) permits the required information to be supplied in phases, without undue further delay, when a full investigation cannot be completed inside that window.
That phased-reporting provision matters here because missing public details do not by themselves establish a missed deadline: an initial notification can precede a completed investigation. The ICO also says breaches affecting individuals in EEA countries engage the EU GDPR, and that organizations should establish the relevant European lead supervisory authority before naming a responsible regulator.
No Revolut first-party statement, remediation detail, or confirmed regulatory notification was available in the researched materials; this should not be read as implying the company has not responded publicly. Open questions include how the fraudulent request passed validation, how affected customers were notified, and how recurrence would be prevented, none of which the evidence establishes as failures.
As background unrelated to the incident, Bitcoin traded at $77,286 in the September 12, 2026 research snapshot, up 0.64% over 24 hours.
Bitcoin price · Research snapshot
$77,286 USD
The disclosure of wallet reference numbers and transaction histories, if authenticated, would touch Bitcoin’s pseudonymity rather than its custody model: no on-chain movement is implied, and the network’s monetary properties, hashrate and difficulty schedule are unaffected by a data disclosure at a single custodian. The underlying UTXO set records nothing about the incident; the exposure, as described, sits entirely in off-chain customer records that a bank maps to its users.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.