πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
β€”β–²0.0%
News

Revolut Handed KYC Files and Bitcoin Histories to a Forged Request

13 Sept 2026by CryptoJazz Admin1 min read3 views
Revolut Handed KYC Files and Bitcoin Histories to a Forged Request

Revolut gave a third party the identity files and bitcoin transaction histories of some of its customers after accepting a request for information sent from a real government agency's email domain. The company confirmed the incident on Saturday. The notices to affected customers went out the day before. Revolut says a limited number of people were involved, has not published a figure, and has not named the agency whose domain was used. No passwords, card PINs, private keys or customer funds were taken.

What went out the door

Four accounts list the same set of data, and it amounts to a complete customer file. The Block, Decrypt, CoinDesk and The Crypto Times each describe name, date of birth and occupation; home address, email and phone number; copies of a passport or driving licence together with the selfie taken to verify it; account statements, IBANs, wallet reference numbers and withdrawal records; and full transaction history, including bitcoin. Nothing in the four accounts separates the crypto records from the banking ones. They went in the same disclosure.

One detail does not sit easily. Decrypt and The Crypto Times both report Revolut saying that no biometric facial telemetry was involved, a line that appears in the same disclosure that lists verification selfies. Neither account explains the distinction, and we could not establish what separates the two categories.

How the request got through

The message came from an unauthorised mailbox inside a genuine government agency's own domain infrastructure. Revolut described what happened in a statement carried by TechCrunch on Saturday and reported in near-identical form by Decrypt.

"Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the company said.

CryptoSlate, The Crypto Times and Crypto Briefing all say the email passed SPF, DKIM and DMARC, the three checks a receiving mail server runs to confirm a message really came from the domain it claims. The Block carries no such detail, and Decrypt says only that the request arrived with valid domain authentication. The claim is credible and it is not confirmed by the outlets closest to the company. CoinDesk alone describes the impersonation as AI-assisted. On the sequence that ended it, CoinDesk and The Crypto Times agree: Revolut acted on the request believing it authentic, then contacted the agency directly and learned the mailbox was not authorised. The email address has since been blocked.

Nobody has said how many

Revolut calls the number limited. CoinDesk puts the gap plainly, writing that the company has yet to disclose how many customers were affected. The on-chain investigator ZachXBT said on Telegram that the disclosure looked small in scale and may have been aimed at high-net-worth customers; The Block, Decrypt, CoinDesk and Crypto Briefing all carry that reading, none of them publishes his exact wording, and it is his assessment and not the company's. Mark Karpeles, who ran Mt. Gox, circulated a copy of the customer notice on Saturday and argued that naming the compromised agency would let other banks and exchanges check whether demands had reached them from the same place. Revolut says it alerted the agency, law enforcement and its regulators. It has named none of them.

A breach with nothing stolen

Attacks that borrow a trusted sender's own domain have been running through this sector all month, and phishing emails reached Trezor users from Trezor's own domain on Thursday of last week. The difference here is that nothing had to be taken from Revolut's systems. The data was asked for and handed over. A year's tally of stolen keys against code bugs would not record this at all, because no coins moved and no wallet was touched. What a full bitcoin history paired with a home address and a passport scan is worth to whoever holds it now is the open question, and the answer depends on people who are not talking. Revolut has not said whether it will publish a count. The agency that owns the domain has said nothing at all.

Read also: Blockstream Refuses a 10% Bounty for Liquid's Missing 598 BTC

← All news