Revolut Fake Government Email Exposed Bitcoin (BTC) Records, Alerts Sent Sep. 11

Revolut confirms a fake government agency email exposed passports, selfies and Bitcoin (BTC) transaction records; alerts went out Sep. 11, funds unaffected.

(09:34 AM UTC)
4 min read
AI SummaryAI
  • Revolut confirmed a fake government email exposed customer files including Bitcoin transaction records
  • Disclosed data included passports, verification selfies, IBANs and Bitcoin wallet reference numbers
  • ZachXBT said alert emails reached affected customers on Friday, Sep. 11
  • Revolut alerted police and regulators and says systems and customer funds are unaffected
k7rq2fdm

Fake Government Email, Genuine Domain

Revolut has confirmed that a single fraudulent email, sent from what looked like an official government channel, tricked the fintech into handing over customer files — including records tied to Bitcoin transaction histories (BTC). The message arrived from a genuine government agency’s email domain and carried valid domain authentication credentials, so the company fulfilled it under what it describes as the reasonable belief that the request was authentic. In a statement, Revolut called the incident a “sophisticated external impersonation attack” in which an unauthorized third party used a legitimate government agency domain email to submit fraudulent requests for information, adding that its systems and customer funds were unaffected. The bank says it blocked the sender as soon as the problem was spotted, alerted the agency, the police, and its data protection and financial regulators, and contacted what it calls a limited number of affected customers. What the company has not disclosed is which agency’s domain was used, citing a live police investigation — leaving open whether a government mailbox was hijacked or whether someone already inside it pressed send. Blockchain investigator ZachXBT, who first flagged the leak, said it appeared to affect a small group of users and looked aimed at wealthy ones. For anyone following the Bitcoin news cycle, the case lands differently from a typical exchange breach: no keys or funds moved, but the material at stake converts on-chain activity into a named, locatable person. By Revolut’s own account, the attacker only had to write an email and wait; the costly failure happened inside the bank’s own compliance process.

Passports, Selfies, Wallet References

The customer notice at the center of the incident — shared publicly by ZachXBT in his investigation channel — lists the categories of data Revolut says went out. They include full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers, alongside copies of identity documents such as passports and driver’s licences, plus the selfies customers supplied for identity checks. Revolut drew one distinction: biometric facial telemetry, meaning the face template built from a photo, was not involved — but the photo itself was. Account statements formed another disclosed category, and those statements contained IBANs, account status, account-opening dates and Bitcoin wallet reference numbers, together with withdrawal records and full transaction histories. The notice lists categories of information that may have been disclosed; it does not establish that every affected customer had every record on file, and it does not state that private keys, account passwords or full payment card details were included. ZachXBT said multiple customers received alert emails on Friday, Sep. 11, but neither he nor the notice portion shown in his post gave a confirmed count of affected users. The backdrop matters: Revolut serves more than 80 million customers globally, received conditional US bank approval from the Office of the Comptroller of the Currency on Sep. 3, and began rolling out its EURR stablecoin to customers in Denmark, Poland and Portugal on Aug. 26 — an expansion that raises the stakes of its data-handling record. Users weighing custodial platforms against self-custody can compare options in our guide to the best crypto exchanges.

Social Engineering Beats Systems

In our reading, the lesson is that the perimeter held and the process failed: no exploit touched Revolut’s infrastructure, yet a well-crafted impersonation email extracted some of the most sensitive records a crypto holder can have. The durable risk is identity, not balances — a password resets in a minute, a passport does not, and pairing home addresses with wallet references creates phishing and physical-targeting exposure that on-chain data alone never could. The regulatory benchmark is explicit: the UK Information Commissioner’s Office breach guidance requires organizations to report certain personal data breaches within 72 hours and notify individuals without undue delay when risk is high. Whether the affected group skews toward crypto whale-scale holders remains unconfirmed.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.