The disclosure surfaced on September 12, 2026, when Revolut confirmed to TechCrunch that it had released customer information after receiving fraudulent requests from what appeared to be a genuine government agency email address. No firewall was breached. No password was cracked. Someone simply asked, convincingly. For related coverage, see CFTC Probes Polymarket Trades: Biden Pardons, Iran, Google.
Revolut said its systems and customer funds were unaffected. That distinction matters: this is a data disclosure, not a wallet drain. The company has been aggressively expanding its crypto footprint, including its EURR stablecoin launch, which makes the exposure of financial records especially awkward. For related coverage, see SEC Delays Teucrium 2x Short XRP ETF to October 11.
What the reported Revolut data leak exposed
The customer notification reviewed by TechCrunch listed a deep trove of identity data: dates of birth, postal and email addresses, phone numbers, and copies of passports or driver’s licenses.
The notice also said verification selfies, account statements and transaction histories may have been included. Crucially, those categories were flagged as possibly affected, not universally exposed for every customer.
The Bitcoin angle comes from Decrypt, which reported the notice described financial records including IBAN and wallet reference numbers, withdrawal records and full transaction histories, Bitcoin among them. That specific detail has not been independently checked against the original notice.
To be clear about the limits: there is no evidence that Bitcoin funds, private keys, passwords or account access were compromised. What leaked was information, the kind that lets someone map who you are and what you hold.
How the fake government request opened the door
The headline claim rests on a single mechanism: the request was fake. Revolut said the fraudulent messages arrived from a legitimate government agency email domain, which is what made them convincing enough to act on.
Beyond that, the picture is deliberately thin. Revolut has not named the impersonated authority, the jurisdiction, the request channel, or how its verification process handled the demand. None of those procedural details should be assumed.
One unverified theory circulating is that valid domain-authentication credentials explain why Revolut fulfilled the request. Decrypt described this possibility, but according to unconfirmed reports only; email headers, authentication results and a technical postmortem were never made public.
Here is the useful context. Email authentication standards like SPF, DKIM and DMARC verify that a message actually comes from the domain it claims, as CISA’s BOD 18-01 explains. But passing those checks only proves where an email came from. It says nothing about whether the sender is entitled to demand customer records. Those are two separate decisions, and conflating them is how impersonation scams win.
What remains unknown about the Revolut disclosure
Revolut told TechCrunch a limited number of customers were affected and had been contacted directly, but declined to disclose the exact count, the government agency, or whether the exposure was confined to one market.
The company said it blocked the email address and alerted the relevant government agency, law enforcement and regulators. It has not identified any of them, and no regulatory investigation, enforcement action or fine has been established.
According to unconfirmed reports, on-chain investigator ZachXBT assessed that the incident targeted high-net-worth users, an assessment TechCrunch attributed to him. No original investigator post or targeting evidence was fetched, so treat it as a lead, not a finding.
The potential consequences are the obvious ones: identity theft and financial-privacy risk for people whose passports and holdings may now sit in the wrong hands. Those are risks, not observed outcomes. No confirmed fraud, fund theft or physical harm has been tied to this leak.
For crypto users, the leak revives an old grievance about mandatory identity collection. Marc Zeller, founder of the Aave Chan Initiative, said his data had been leaked and used the moment to attack KYC data-retention practices.
Woke up to all my data leaked by @Revolut.
Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way. pic.twitter.com/RimOBQr7DW
— Marc Zeller (@mzeller) September 12, 2026
Source: @mzeller on X
His view is a pointed opinion, not a forensic conclusion. But it lands in a market already jittery about custody and disclosure risk, themes that echo through recent stories like Blockstream’s refusal to pay ransom over a Liquid Bitcoin hack and the broader regulatory churn seen when the SEC reportedly shelved a meeting on its crypto framework.
Bitcoin itself barely flinched. The asset traded near $77,338, down roughly half a percent on the day, with no incident-linked price reaction established. This story is about data, not price.
So the real question hangs over the industry: if a well-resourced fintech can be socially engineered into surrendering passports and transaction histories with nothing more than a convincing email, who exactly is protecting the identity data that KYC rules force everyone to hand over?
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.