Revolut reportedly exposed customer know-your-customer (KYC) data and Bitcoin transaction histories after a spoofed government request, an alleged disclosure that touches the identity records and on-chain footprints of an unknown number of account holders.
Revolut reportedly exposed customer know-your-customer (KYC) data and Bitcoin transaction histories after a spoofed government request, an alleged disclosure that touches the identity records and on-chain footprints of an unknown number of account holders. The report is based on a customer notice circulated by an on-chain investigator and has not been independently confirmed, and it names no financial theft.
- What to Know: Reports say Revolut disclosed customer KYC material and Bitcoin transaction histories, including wallet reference numbers and withdrawal records, to an unauthorized party.
- What to Know: The disclosure allegedly followed a fraudulent request purporting to come from a government agency, submitted through an email account on an official government domain that passed domain authentication checks.
What customer data Revolut reportedly exposed
In a report published on September 12, 2026, crypto.news attributed the alleged disclosure to a Revolut customer notice shared by on-chain investigator ZachXBT, according to the outlet’s account of the notice. The original notice was not independently authenticated, and the report distinguishes what the notice states from what has been confirmed by the company. For related coverage, see Bitcoin Rises as Inflation Data Sets Stage for Fed Decision.
The reported notice lists identity documents and verification selfies among the disclosed data, while stating that biometric facial telemetry was not included. That distinction matters because a selfie image is a static file, whereas facial telemetry is the mathematical template used for live authentication. For related coverage, see Grayscale Compares Bitcoin and Zcash Mining Profitability.
The notice, as reported, also lists account statements containing Bitcoin wallet reference numbers, withdrawal records and full transaction histories including Bitcoin transactions. The account does not establish that every affected customer had every category of record exposed. This echoes a separately reported Revolut incident involving passports and Bitcoin records, though the two reports should not be conflated.
For Bitcoin holders, the sensitivity here is the linkage between a verified legal identity and a set of on-chain reference points. No evidence in the reported material indicates that funds, wallet credentials or private keys were compromised; the disclosure concerns records, not spending authority.
The spoofed government request behind the reported disclosure
The reported sequence places the exposure after a fraudulent request framed as coming from a government agency. According to the report, an unauthorized email account using an official government agency domain sent the request, and that message passed domain authentication checks rather than originating from a lookalike address.
The distinction is technical but consequential. Domain authentication protocols such as SPF, DKIM and DMARC verify that a message genuinely originates from the claimed domain; a message passing those checks from a real government domain is far harder to flag than a spoofed lookalike. How the account came to send from that domain remains unknown.
The fetched report says the shown notice does not identify the government agency, the request date, the disclosure date or a confirmed affected-customer count, as detailed in the crypto.news account of the notice. ZachXBT reportedly said multiple customers received alerts on September 11. The available material does not establish how the request was authenticated internally or which controls, if any, failed.
ZachXBT assessed the incident as likely limited in size and potentially targeting high-net-worth users, according to crypto.news. That assessment is a secondary paraphrase, and according to unconfirmed reports the company notice itself does not confirm any selection criteria or scope.
What remains unverified about the Revolut report
The strongest verification need is the underlying customer notice itself, which was accessible only through secondary reporting; no directly fetched company statement or regulator filing authenticated it. A Revolut response and the identity of the source notice remain the primary items to confirm.
The number of affected customers, the exact data fields involved, the incident timing and whether customers were formally notified are all unresolved in the supplied material. According to unconfirmed reports no funds were lost, but the absence of a described intruder withdrawal is not a verified zero-loss finding.
Under UK Information Commissioner’s Office guidance, a personal data breach includes unauthorized disclosure and sending personal data to an incorrect recipient, and theft of funds is not required to meet that definition, per the regulator’s breach guidance. That guidance requires notification of notifiable breaches without undue delay and no later than 72 hours after awareness, with high-risk breaches also requiring notice to affected individuals without undue delay.
The same guidance requires organizations to record all personal data breaches, including those that are not notified, and permits required notification details to be supplied in phases without undue further delay. These are general UK rules; they are not evidence that Revolut notified a regulator, missed a deadline or committed any violation, and the applicable jurisdiction and responsible entity are not established in the reported material.
Revolut’s regulatory posture is itself in transition, having received conditional OCC approval for a U.S. national bank charter, which raises the stakes for how any confirmed data-handling incident is disclosed. Reported exposure incidents at payment platforms also sit alongside merchant-side risks such as the BTCPay emergency patch that exposed a merchant-side Bitcoin security risk.
Market conditions provide only distant background and no measure of incident impact. Bitcoin traded near $77,331 with a 24-hour move of about 0.10%, a market capitalization near $1.55 trillion and roughly $33.2 billion in daily volume, while the broad Fear & Greed Index sat at 63, in Greed territory.
None of this alters Bitcoin’s base-layer properties. The threat in a KYC disclosure is to privacy and identity linkage, not to the protocol itself; a Bitcoin transaction remains a UTXO transfer validated across the network regardless of which custodian holds a customer’s identity file. As users weigh custodial exposure, the durable defenses stay the same: minimizing reused addresses, and where feasible, moving toward self-custody so that on-chain history is not permanently welded to a single institution’s KYC database.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.