Fake Government Email Led Revolut to Disclose Customers’ Bitcoin Records
Key Takeaways
- •The disclosure included names, contact details, identity documents, account statements, IBANs, withdrawal records, and complete transaction histories.
- •Bitcoin wallet references and transaction histories were among the exposed records, while private keys, passwords, and full payment card details were not disclosed.
- •Revolut has not confirmed how many customers were affected or explained how the unauthorized requester accessed the government agency’s email domain.
- •The company has not said whether regulators were notified or detailed how the fraudulent request bypassed its controls.
- •The incident is separate from Revolut’s conditional US bank charter approval and launch of its EURR stablecoin.

Revolut disclosed customer data, including Bitcoin transaction histories, to an unauthorized party after receiving what it believed was a legitimate government request. The request used an official government agency’s email domain and passed standard domain authentication checks.
The company said it fulfilled the request because the message appeared genuine. Revolut has not identified the agency whose domain was used or explained how the unauthorized sender gained access to it.
⚠️ ALERT: Revolut falls for a FAKE government request, exposing sensitive personal information of customers in a disturbing data breach. Revolut disclosed that it complied with a fraudulent government request using a spoofed official email and valid credentials, exposing PII… pic.twitter.com/3RPO6OYs1N
— Coin Bureau (@coinbureau) September 12, 2026
https://x.com/coinbureau/status/2098684872395301092?ref_src=twsrc%5Etfw
What Data Was Exposed
The disclosed records included a broad range of personal and financial information, including customers’ full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers.
Identity documents such as passports and driver’s licenses were also shared, along with selfies submitted during identity verification. Revolut said biometric facial telemetry data was not included.
Financial information made up a substantial portion of the disclosure. The records sent to the unauthorized requester included account statements, IBANs, account-opening dates, withdrawal records, and full transaction histories.
Bitcoin wallet reference numbers appeared in the account statements, and Bitcoin transaction histories were included in the disclosed records. This could link crypto users’ financial activity to their identities.
Revolut said private keys, account passwords, and full payment card details were not included.
Who Was Affected
On-chain investigator ZachXBT shared the customer notice on Telegram on September 11. He said the incident appeared limited in scale and may have targeted high-net-worth users. Revolut has not confirmed how many customers were affected.
Revolut serves more than 80 million customers worldwide, although that figure represents its total user base and does not indicate the number involved in this incident. The customer notice also does not establish whether every affected customer had each type of record on file or explain how the individuals were selected.
Regulatory and Security Context
The UK Information Commissioner’s Office says data breaches can result in identity theft, fraud, and financial loss. Regulators require organizations to report certain breaches within 72 hours and notify affected users promptly.
The screenshot of the notice shared by ZachXBT does not confirm whether Revolut notified a regulator or when the company learned that the request was fraudulent. Revolut has not publicly commented beyond the customer notice and has not identified the agency whose email domain was used. Further public updates would be needed to clarify the number of affected customers, whether regulators were notified, how the fraudulent request passed the company’s controls, and whether additional records were involved.
The disclosure comes as Revolut expands its services. On September 3, the company received conditional approval for a US bank charter from the Office of the Comptroller of the Currency. In August, it launched its euro-backed stablecoin, EURR, to selected European customers.
Those developments are separate from the data disclosure. Revolut has not identified any affected users as being based in the United States.
Source: https://coincentral.com/fake-government-email-fooled-revolut-into-handing-over-your-bitcoin-records/