The account of the Revolut data breach comes from a report published by Lawrence Mondal on crypto. news on September 12, 2026, describing a purported customer notice about the disclosure of records following a fraudulent government-agency request.
Revolut has reportedly disclosed a data breach in which customer records, including passports, account statements and Bitcoin transaction histories, were handed to an unauthorized party posing as a government agency. The Revolut data breach, described in a customer notice circulated publicly, involved the disclosure of sensitive records rather than any confirmed intrusion into customer accounts or theft of funds.
WHAT TO KNOW
- Revolut has reportedly disclosed a data breach affecting customer records.
- The reported exposure names passports, account statements and Bitcoin records among the data categories involved.
What Revolut disclosed about the data breach
The account of the Revolut data breach comes from a report published by Lawrence Mondal on crypto.news on September 12, 2026, describing a purported customer notice about the disclosure of records following a fraudulent government-agency request. That reporting verifies the published account, not the authenticity of the underlying notice. For related coverage, see Bitcoin Rises as Inflation Data Sets Stage for Fed Decision.
According to unconfirmed reports, the notice was shared publicly by on-chain investigator ZachXBT and states that the request came from an unauthorized account using an official government-agency email domain that passed domain authentication checks. The agency is not named in the material that has surfaced. For related coverage, see Grayscale Compares Bitcoin and Zcash Mining Profitability.
Customer alert emails reportedly went out on September 11, 2026, though the shown notice gives no date for the underlying request or the disclosure itself. Whether Revolut has issued an official incident page, filing, or postmortem could not be independently confirmed.
Passports, statements and Bitcoin records named in the exposure
The reported data categories span identity documents such as passport or driver’s-licence copies, verification selfies, account statements, IBANs, withdrawal records and full transaction histories including Bitcoin activity, attributed to ZachXBT or the notice he shared. The material does not establish that every category applied to every affected customer.
In the crypto.news account, Bitcoin wallet reference numbers appeared within the listed account statements, while biometric facial telemetry data was described as not involved. These are attributed notice contents, not independently authenticated findings.
The exposure of transaction records is a records-disclosure event, not evidence of an account takeover. Nothing in the reporting indicates that Bitcoin was stolen, that private keys or seed phrases leaked, or that passwords were compromised, and readers should not infer wallet balances, addresses or credentials from the mention of Bitcoin records. The distinction matters for anyone holding Bitcoin at a custodian: exposure of a statement listing past activity is a privacy failure, not a loss of self-custodial control, which is one reason a share of users route repeat Bitcoin purchases toward withdrawal to personal wallets.
Data disclosure of this kind carries downstream phishing and social-engineering risk once identity documents and financial histories are combined, a pattern also seen when merchant-side flaws create Bitcoin security exposure at the payments layer rather than at the protocol layer. The Bitcoin network itself is unaffected by a custodian’s records handling.
Breach scope and response details requiring verification
Key facts remain unverified in the available material: the affected-customer count, the timing of the fraudulent request versus the notification, the access method, and the precise record scope. PANews attributes to ZachXBT an assessment that the affected group may be limited and that high-net-worth users may have been targeted, but no company-confirmed figure exists.
No confirmed containment steps, customer guidance or regulator notifications have been obtained, and any description of Revolut’s response should wait on first-party evidence. These are gaps in the surfaced reporting, not a finding that Revolut has withheld the details publicly.
Under the UK Information Commissioner’s Office, unauthorized disclosure and sending personal data to an incorrect recipient both meet the definition of a personal data breach, so a systems intrusion is not required. Certain notifiable breaches must be reported within 72 hours of awareness where feasible, with high-risk individuals told without undue delay; these are general rules, and no conclusion about Revolut’s jurisdiction, compliance or liability follows from them.
The reported disclosure has no demonstrated connection to Bitcoin’s market behavior, which points to background conditions rather than a reaction to this incident, and the network’s monetary properties, fixed issuance and self-custody model are untouched by a custodian’s data handling. Prior incidents such as Blockstream’s refusal to pay a ransom over a Liquid-related loss underline that custodial and sidechain risks sit apart from base-layer Bitcoin security.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.