📈 Get daily crypto insights that make you smarter about your money

Revolut Handed Over Customer Bitcoin Records to a Fake Government Email — Here Is What Was Exposed

Revolut handed over customer identities, selfies, and full Bitcoin transaction histories after falling for a fraudulent request sent from an unauthorized account on an official government agency’s email domain — an incident revealed by on-chain investigator ZachXBT.

By Keisha Williams | September 12, 2026

The Hook: A Fake Email That Passed Every Check

According to a Revolut customer notice shared on Telegram by ZachXBT, one of the best-known independent investigators in crypto, the request came from an unauthorized email account operating on a government agency’s official email domain. Critically, the message passed domain authentication checks — the industry-standard filters designed to verify that an email really comes from where it claims to come from.

“As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request,” Revolut’s notice said. In plain terms: the spoof wasn’t a lookalike address like “revolut-security.net” tricking customers. Someone used the real agency domain itself, and Revolut’s checks correctly validated it — which is exactly what makes this incident unsettling.

The notice does not name the agency, explain how the unauthorized sender obtained access to its email domain, or give a date for the request. ZachXBT said multiple customers received an alert email on Friday, September 11, but no confirmed count of affected users exists. He described the incident as likely limited in size and said it appeared to have targeted high-net-worth users — a claim Revolut’s notice does not confirm.

The Evidence: What Actually Got Exposed

The disclosed records read like a complete financial profile. According to the notice, the unauthorized recipient may have obtained:

  • Identity details — full names, dates of birth, and occupations
  • Contact information — postal addresses, email addresses, and telephone numbers
  • Identity documents — copies of passports or driver’s licences, plus the verification selfies customers submitted when opening accounts (Revolut says biometric facial telemetry data was not involved)
  • Account records — IBANs, account status, account-opening dates, and Bitcoin wallet reference numbers
  • Transaction data — withdrawal records and full transaction histories, including Bitcoin transactions

For crypto users, that last category is the sensitive one. A Bitcoin wallet reference number paired with a name and a full transaction history gives the recipient a detailed map of someone’s crypto finances — not their coins themselves, but enough to know exactly how much moved, when, and to where. The notice does not say that wallet private keys, passwords, or full payment card details were included, and it does not establish that every affected customer had every type of record on file.

Importantly, the notice describes a deceptive disclosure — not a system intrusion. There is no indication an attacker broke into Revolut’s systems, accessed customer accounts directly, or withdrew funds. Revolut serves more than 80 million customers globally, per an August company announcement, though that figure describes the business’s size, not the number affected here.

The Core Conflict: When Compliance Becomes the Vulnerability

This incident exposes an awkward truth about modern finance: the machinery built to verify requests can become the attack itself. Banks and fintechs like Revolut process large volumes of government information requests — for sanctions screening, fraud investigations, and tax matters. Refusing a legitimate request can mean regulatory penalties. Fulfilling a forged one means handing a stranger your customers’ financial lives.

Domain authentication was supposed to solve the forgery problem. Email standards like SPF, DKIM, and DMARC cryptographically confirm that a message genuinely originated from its claimed domain. But those checks verify the domain, not the human behind the keyboard. If an attacker gains access to any mailbox on the agency’s domain — through a compromised employee account, for instance — their forged request becomes indistinguishable from a real one. Revolut’s “reasonable belief” framing suggests its own processes worked as designed; the failure happened upstream, at the agency’s email system.

The stakes are framed by UK regulator guidance. The Information Commissioner’s Office warns that personal data breaches can lead to identity theft, fraud, and financial loss, and requires organizations to report certain breaches to the regulator within 72 hours of becoming aware of them, and to notify affected individuals without undue delay when the risk is high. The screenshot shared by ZachXBT does not say whether Revolut has notified a regulator or when it first learned of the request.

Market Implications: Timing Could Be Better

The disclosure lands during a sensitive stretch for Revolut’s crypto and banking ambitions. On August 26, the company began offering its euro-backed EURR stablecoin to selected customers in Denmark, Poland, and Portugal, with wider European availability planned. And on September 3, Revolut received conditional approval from the Office of the Comptroller of the Currency for a proposed U.S. national bank in Stamford, Connecticut — a project backed by roughly 95 million USD in initial capital that could open in 2027 if it clears remaining hurdles, including FDIC deposit insurance, Federal Reserve approval, and final OCC authorization. Until then, Revolut’s U.S. banking services run through Lead Bank.

Neither expansion is directly connected to this incident, and the notice does not identify any affected customer as being in the United States. But trust is the core product of any bank — and of any crypto platform. Incidents like this one give regulators reviewing those pending U.S. approvals another question to ask, and give competitors an easy talking point.

For affected customers, the practical risk is targeted fraud. Someone holding your ID document, selfie, address, phone number, and full crypto transaction history is well-equipped for convincing impersonation scams — the “your account is compromised” phone calls that have drained countless crypto users. Notably, Revolut’s own U.S. security guidance tells customers to use in-app support chat to verify suspicious contacts and reminds them the company will never ask for verification codes over the phone.

The Verdict: Verify the Verifiers

The uncomfortable lesson is that individual diligence could not have prevented this breach. Customers did nothing wrong — their bank fulfilled a request that looked genuine because, technically, it came from a genuine domain. The fix has to be institutional: out-of-band verification for sensitive data requests, where the bank confirms through a separate channel that the agency actually sent it, rather than trusting the email alone.

For regular investors, two takeaways. First, if you’re a Revolut customer, be extra skeptical of any call or message referencing your account — attackers with your real records can be alarmingly convincing. Second, remember that keeping significant crypto holdings on any centralized platform means trusting not just its security team, but every process that touches your data. Self-custody — holding coins in your own wallet — limits how much of your financial life can be handed over by mistake. This time, it was one fintech and a forged email. The next one may not wait for a Friday alert.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

9 thoughts on “Revolut Handed Over Customer Bitcoin Records to a Fake Government Email — Here Is What Was Exposed”

  1. the request passed actual domain authentication checks. if that works on revolut it works everywhere, this is way bigger than one bank

    1. domain auth passing means someone got a legit looking account on the agency side. that failure belongs to the agency too, not just revolut

  2. wire desks have done callback verification since the 90s. a request that big should never clear on email alone, whatever the domain said

  3. a selfie, id docs and the full btc history handed over because of one spoofed email. banks do callback verification for wire fraud, why wasnt revolut doing that here

  4. full bitcoin histories plus selfies handed to a scammer. those customers are doxxed for life, revolut owes them way more than an apology

    1. compensation will be some pro-rata voucher lol. the selfies and histories are already copied and resold, no apology undoes that

    2. zachxbt catching this before revolut’s own security team noticed tells you everything about where their priorities are

  5. this is why not your keys not your coins isnt just a meme. your kyc data sitting on an exchange is a liability, they just hand it over

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,427.00-1.6%ETH$2,540.78-2.5%SOL$102.00-1.2%BNB$735.26+0.5%XRP$1.37-1.3%ADA$0.2088-1.4%DOGE$0.0851-1.4%DOT$1.04-3.6%AVAX$7.43-3.4%LINK$11.57-2.9%UNI$6.39+1.2%ATOM$1.63-5.7%LTC$53.99+0.5%ARB$0.1441-2.1%NEAR$2.39-11.6%FIL$0.8081-1.6%SUI$0.7264-2.7%BTC$77,427.00-1.6%ETH$2,540.78-2.5%SOL$102.00-1.2%BNB$735.26+0.5%XRP$1.37-1.3%ADA$0.2088-1.4%DOGE$0.0851-1.4%DOT$1.04-3.6%AVAX$7.43-3.4%LINK$11.57-2.9%UNI$6.39+1.2%ATOM$1.63-5.7%LTC$53.99+0.5%ARB$0.1441-2.1%NEAR$2.39-11.6%FIL$0.8081-1.6%SUI$0.7264-2.7%
Scroll to Top