Revolut reportedly disclosed customer passports and Bitcoin transaction histories in response to a fake government request, according to unconfirmed reports circulating on September 11 and 12, 2026.
Revolut reportedly disclosed customer passports and Bitcoin transaction histories in response to a fake government request, according to unconfirmed reports circulating on September 11 and 12, 2026. The disclosure, if confirmed, would expose the identity records and on-chain financial histories of Revolut customers without any systems intrusion, raising direct questions about how Bitcoin-holding users are protected when custodial platforms field impersonated law-enforcement demands.
For Bitcoin holders, the significance is specific: a custodial account statement that references Bitcoin wallet identifiers and full transaction histories can be used to deanonymize on-chain activity, linking real-world identity documents to spendable UTXOs long after the fact. The reported episode is a reminder that self-custody, not custodial convenience, is the only structure that keeps a user’s Bitcoin transaction graph outside a third party’s disclosure pipeline. For related coverage, see Bitcoin Long-Term Holders Sold 539,000 BTC: CryptoQuant.
WHAT TO KNOW
- The headline states passports and Bitcoin transaction histories were disclosed.
- The headline states the disclosure followed a fake government request.
What Revolut Disclosed: Passports and Bitcoin Transaction Histories
The two data types named in the headline are passports and Bitcoin transaction histories. The supplied headline does not specify whether “passports” refers to full scans, copies, passport numbers, or another format, and that detail should not be inferred.
Secondary reporting describing a Revolut customer notice lists a broader set of identity information said to be involved: full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers. That same reporting says copies of identity documents such as passports or driver’s licences and verification selfies were included, while excluding biometric facial telemetry data.
The reported records also extended to account statements containing IBANs, account status, opening dates and Bitcoin wallet reference numbers, alongside withdrawal records and full transaction histories including Bitcoin transactions. Other outlets have similarly described the incident as a reported exposure of KYC data and Bitcoin histories, though the underlying notice has not been independently authenticated.
Nothing in the available material indicates that private keys, account credentials, passwords or customer funds were exposed or stolen. The reported categories describe records held by the custodian, not control over the assets themselves.
The Fake Government Request Behind the Disclosure
The headline characterizes the request that prompted the disclosure as fake. In the account carried by secondary reporting, an unauthorized account using an official government agency email domain requested customer information, and valid domain authentication credentials reportedly led Revolut to believe the request was authentic.
The specifics of the Revolut fake government request remain thin. The available material does not identify the impersonated authority, the requester, the jurisdiction, or the internal verification process that handled the demand, and those gaps should not be filled by inference. Coverage of how the platform exposed Bitcoin activity in the fake request incident stops short of detailing the submission channel.
Crucially, the reported episode is not established as a systems intrusion, and the headline alone does not establish a legal violation. Regulatory guidance from the UK Information Commissioner’s Office defines a personal data breach to include unauthorized disclosure of personal data and sending personal data to an incorrect recipient, meaning a hack is not required for an event to fall within that definition. Some accounts have instead framed the matter as data reportedly obtained through the impersonated request rather than a network compromise.
What Remains Unknown About the Revolut Disclosure
The affected-customer count, the timing of the request and disclosure, the recipient’s identity, and the full extent of the disclosed records are all unknown from the supplied context. Reporting attributes the September 11 customer alerts to on-chain investigator ZachXBT and says the notice did not name the agency, date the request, or confirm how many customers were affected.
One assessment, that the incident was limited in size and targeted high-net-worth customers, comes from ZachXBT according to unconfirmed reports, and the reported notice does not corroborate it. Whether any given customer had both a passport copy and a Bitcoin history disclosed is likewise unestablished; the listed categories do not establish which records existed for each person.
The available material contains no confirmed Revolut statement, customer-notification detail beyond the reported notice, or remediation information. Any linkage between specific passport records and specific Bitcoin transactions, any misuse of the data, and any financial loss should be treated as unestablished rather than assumed. Related coverage has framed the matter as a reported breach of passports, statements and Bitcoin records while noting the same open questions.
Regulatory context sharpens where those gaps sit. ICO guidance requires notification of a notifiable breach within 72 hours of awareness where feasible, and notification of affected individuals without undue delay where the risk to their rights and freedoms is high; Article 33(4) further permits required breach information to be supplied in phases without undue further delay when a full investigation cannot be completed in time. The applicable jurisdiction, the awareness timestamp and the notification status here are unknown, so none of this establishes that Revolut missed a deadline or that an investigation exists.
For Bitcoin itself, the network’s fundamentals are indifferent to custodial record-keeping: block issuance continues on its roughly ten-minute cadence toward the next difficulty adjustment, and the deanonymization risk in this episode flows entirely from custodial data, not from any weakness in the base layer. The durable takeaway for holders tracking their own UTXO privacy is that transaction histories surrendered by a custodian cannot be clawed back from a recipient once disclosed.
Additional source references: source document 1, source document 2.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.