Revolut fake government request leaks passports and bitcoin histories

On September 11, 2026, Revolut began telling a “limited” number of customers it had handed their passports, selfies, addresses and full transaction histories, including bitcoin activity, to a fake government request.

Voxel shield in deep blue with white ID letters, cracked, with debris cubes scattered on a dark background

Revolut didn’t get hacked in the usual sense. Nobody broke into its servers. Someone simply asked for customer data while posing as a government agency — from a mailbox inside that agency’s real email domain — and Revolut handed it over. On Friday, September 11, the fintech started telling affected customers what had been released: passports, selfies, addresses and full transaction histories, bitcoin activity included.

For crypto holders, that last part is the one that matters. A leaked password is a bad day. A leaked passport next to a record of your bitcoin is a permanent problem.

Key facts

  • Revolut released customer data in response to a fraudulent “government” data request sent from a mailbox inside a real government agency’s email domain; the email passed SPF, DKIM and DMARC.
  • Exposed data includes passports or driving licences, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs, account statements, withdrawal records and full transaction histories, including all bitcoin activity.
  • Revolut notified affected customers on Friday, September 11, 2026; it calls their number “limited”, published no figure and did not name the agency.
  • Revolut says funds, passcodes, logins and biometric data were not affected, and it has alerted the agency, law enforcement, data-protection authorities and financial regulators.
  • On-chain investigator ZachXBT first drew attention to the incident and said it may have targeted high-net-worth customers of Revolut, which has 80M+ customers in 30+ countries.

What happened at Revolut?

Revolut received what looked like an official data request from a government agency and complied. The request came from a mailbox set up inside the agency’s own email domain and passed every standard email authentication check. Revolut only realised it was fake after contacting the agency separately — by then, customer files had already gone out.

According to CoinDesk, Revolut blocked the sender and alerted the agency, law enforcement, data-protection authorities and financial regulators. TechCrunch quotes the company describing a “sophisticated external impersonation scam” and saying its systems and customer funds are unaffected. Revolut calls the number of affected customers “limited” but has not published a figure, named the agency or said which markets were involved.

The story surfaced publicly thanks to on-chain investigator ZachXBT, who said the request may have been aimed at high-net-worth customers. That fits the data that was asked for: not a random sample, but exactly the files that tell you who has money and where they live.

What data did Revolut hand over?

The released files cover nearly everything a KYC process collects plus the financial trail behind it. As CryptoSlate summarised, the package included:

  • Identity documents — passports or driving licences — and verification selfies
  • Names, dates of birth, occupations and home addresses
  • Emails and phone numbers
  • IBANs, account statements and withdrawal records
  • Full transaction histories, including all bitcoin activity

Revolut says passcodes, logins and biometric data were not part of it, and funds were not touched. That is true and useful — nobody can log into these accounts with what was taken. It is also beside the point. The dangerous part of this leak isn’t account access. It’s what the data says about the people behind the accounts.

Why is leaked KYC data worse than a leaked password?

Because you can’t rotate it. After a password leak you change the password and move on. After a KYC leak your passport number, your face, your date of birth and your home address stay the same — and stay valid for whoever holds the copy. KYC databases are honeypots with no reset button.

You can change a password. You can’t change your passport or your face.

Add a full bitcoin history to that file and it becomes something worse: a targeting kit. An ID, a home address and a list of what someone bought, when and how much is exactly what a “wrench attack” needs — physical coercion aimed at people known to hold crypto. Digital theft needs keys; a wrench attack only needs to know who you are and where you sleep.

The leak also feeds ordinary fraud. A caller who knows your IBAN, your recent withdrawals and your date of birth sounds a lot like your bank. Expect phishing that quotes real details back to you.

How did a fake request pass as real?

It came from the right domain. The fraudulent request was sent from a mailbox inside the agency’s genuine email domain, so SPF, DKIM and DMARC all passed. To Revolut’s mail filters it looked exactly like the real thing. Only an out-of-band check — contacting the agency separately — exposed it, after the data had left.

That is the same weak link as two days earlier, when attackers used a breached newsletter provider to send a fake security alert from Trezor’s real domain (we covered the Trezor and BitBox phishing campaign here). In both cases, “authenticated” email did its job perfectly and still delivered an attack. Authentication proves where a message came from, not that the sender is who you think. Mark Karpelès argued that Revolut naming the agency would help other institutions check whether they received the same request.

The irony wasn’t lost on crypto users. Marc Zeller of the Aave Chan Initiative complained that Revolut had just demanded a large amount of personal data from him under threat of account closure. Collect everything, and everything is what leaks.

What should crypto holders on Revolut do now?

If Revolut notified you, assume the data is out; either way, reduce what your data is worth to an attacker. Move bitcoin you intend to hold into self-custody, stop leaving a full crypto history where it doesn’t need to be, and treat any call or email that quotes your account details as suspicious by default.

  1. Move long-term BTC off the app. Withdraw to a wallet whose keys you hold. It won’t erase the history, but it takes the balance out of a custodial account.
  2. Don’t trust a caller because they know your details. Knowing your IBAN or last withdrawal no longer proves anything. Hang up and call back through the official app.
  3. Keep your holdings private. Don’t discuss amounts publicly or link your identity to addresses you use.
  4. Minimise going forward. Each platform that stores your ID plus your crypto activity is another copy of this file waiting to leak.

What it means for swap users

Data you never hand over can’t be released to a fake request. SwapZilla swaps need no account, no ID upload and no email: coins go from your wallet to your wallet, and there is no profile tying your passport to your transaction history. Be precise about the limits, though. Exchange providers may still run AML checks on flagged transactions, as our AML policy explains, and a swap doesn’t make you anonymous. For more on-chain privacy, the private route through Monero adds a layer — see is Monero anonymous for what it does and doesn’t hide, and how to swap USDT to BTC privately for a practical walkthrough.

Markets barely reacted. On Saturday BTC traded around $77,300 after a $76,000–79,900 range over 24 hours, with ETH near $2,536 and total crypto market capitalisation at $2.73T.

Final thoughts

Revolut’s systems weren’t breached, and no funds moved. But a single convincing email turned a KYC archive into an attacker’s shortlist of wealthy bitcoin holders, complete with home addresses. The lesson is the same one the Trezor phishing taught this week: authenticated email is not trusted email, and every database holding your identity is a liability you don’t control. The best protection is the data that was never collected.

FAQ

What data did Revolut leak in September 2026?
In September 2026 Revolut released customer data to a fraudulent government data request. The exposed data includes passports or driving licences, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs, account statements, withdrawal records and full transaction histories, including all bitcoin activity. Revolut says funds, passcodes, logins and biometric data were not affected. Customers were notified on Friday, September 11, 2026.
How was Revolut tricked by a fake government request?
Revolut received a data request that appeared to come from a real government agency. It was sent from a mailbox set up inside the agency’s own email domain, so it passed SPF, DKIM and DMARC checks. Revolut complied and only realised the request was fake after contacting the agency separately. It then blocked the sender and alerted the agency, law enforcement, data-protection authorities and financial regulators in September 2026.
How many Revolut customers were affected by the data leak?
Revolut has not published a number. The company described the number of customers affected by the September 2026 fake government request as “limited” and did not name the agency involved or the markets targeted. On-chain investigator ZachXBT, who first drew attention to the incident, said the request may have targeted high-net-worth customers. Revolut has more than 80 million customers in over 30 countries.
What should I do if my Revolut data was leaked?
If your data was part of the September 2026 Revolut leak, assume your ID, address and transaction history are in unknown hands. Be suspicious of any call or email that quotes your account details and contact Revolut only through the official app. Consider moving long-term bitcoin to a self-custody wallet, avoid discussing your holdings publicly, and limit how many platforms store both your ID and your crypto activity.
Can I swap crypto without KYC or an account?
Yes. SwapZilla is a non-custodial swap aggregator that needs no account, no email and no ID upload for a standard swap, so it does not build a profile linking your identity to your transaction history like the one exposed in the September 2026 Revolut leak. It does not make you anonymous: exchange providers may still run AML checks on flagged transactions, as described in SwapZilla’s AML policy.