Editorial cover for crypto story

Revolut Bitcoin Data Breach: Spoofed Government Email Exposed Customer Crypto Histories

The Revolut Bitcoin data breach fake government request incident became public on September 12, 2026, when a UK-based fintech disclosed that it had handed over customer personal records, identity documents, and full Bitcoin transaction histories to an unauthorized third party after treating a spoofed government email as authentic. Customer notices began circulating on September 11, 2026, and the story broke widely the following day after on-chain investigator ZachXBT and former Mt. Gox CEO Mark Karpelès flagged the disclosure online.

Revolut Bitcoin data breach fake government request: How the spoof got past Revolut’s checks

According to the customer notice, the unauthorized sender used an email account created directly within an official government agency’s domain infrastructure, and the message carried valid domain authentication credentials. The email passed Revolut’s standard DMARC, SPF, and DKIM verification, which are the protocols most organizations rely on to confirm that a message genuinely originated from a claimed domain. Revolut fulfilled the request, then separately contacted the agency to verify. The agency confirmed the request was fraudulent. Revolut subsequently blocked the sending address, notified regulators, and applied what it described as precautionary protection measures.

As of 09:13 UTC on September 12, 2026, Revolut had not posted a numbered press release or any statement from its main @Revolut account on X. The @revolutsupport handle replied to a user at 06:42 UTC with the line “We take data protection and privacy concerns very seriously” and nothing else. The first public flag of the breach came from Mark Karpelès, the former Mt. Gox CEO, who posted substantial excerpts of the customer notice on X at 07:06 UTC on September 12. He identified himself as a recipient. His notice arrived in his inbox at 21:59 UTC on September 11 with the subject line “Urgent security update about your Revolut account.”

What customer data was exposed

The data set handed to the attacker is unusually broad for a single disclosure. Revolut’s notice lists full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. It also includes copies of identity documents, specifically passports and driver’s licenses, plus selfies submitted during onboarding. Most damaging for crypto holders, the notice confirms that Bitcoin wallet reference numbers and full Bitcoin transaction histories were released. Revolut states that no funds were lost and that no biometric facial telemetry data was involved or compromised.

ZachXBT, writing on his Telegram channel, said the case appeared relatively small in customer count but skewed toward users with large crypto holdings. He was subsequently blocked by both @Revolut and @revolutsupport on X after posting about the incident. The combination of large crypto holdings, home addresses, phone numbers, and government ID copies creates a textbook targeting list for physical extortion, SIM swap attempts, and home invasion schemes aimed at long-term Bitcoin holders.

Regulatory clock and open questions

Under UK ICO guidance, organizations must report certain personal data breaches within 72 hours of becoming aware and must notify affected individuals without undue delay when the risk to individuals is high. The notice to customers appears to satisfy the individual notification leg, though the timeline between Revolut fulfilling the request, confirming the fraud, and writing to customers has not been disclosed. The number of affected customers has not been disclosed. The government agency whose domain was spoofed has not been named. The mechanism by which the unauthorized sender obtained the ability to create an account inside an official agency domain has not been explained. The original date of the fraudulent request is also not in the notice.

For the broader crypto industry, the incident underscores that authentication protocols only confirm a domain, not the human operating the inbox. A passing DMARC check tells a receiving server that an email was signed by the domain it claims to come from; it does not confirm that the sender is actually a clerk at the named agency. Sophisticated attackers who can mint credentials inside a legitimate domain infrastructure defeat the assumption that authenticated email equals trustworthy email. Treat any inbound request for passport scans and full transaction histories as a high-risk action, regardless of how clean the headers look, and require an out-of-band callback to a known phone number before responding.

Customers who receive a Revolut notice should assume their home address, ID document, phone number, and Bitcoin transaction history are now in hostile hands. Practical steps include enabling a postal forwarding service or virtual address, tightening SIM swap protection with the mobile carrier, rotating email addresses where possible, and reviewing cold storage arrangements so that no single address ties a known identity to a known wallet. The Revolut Bitcoin data breach fake government request case is the clearest reminder yet that authentication is not identity, and that crypto holders are an obvious secondary target whenever ID-linked transaction data leaks.

Source: https://cryptotimes.io/2026/09/12/revolut-handed-over-bitcoin-histories-passports-on-spoofed-government-email

The technical mechanics behind the Revolut Bitcoin data breach fake government request are now being dissected by security teams across the financial sector, and the early consensus is that the attacker exploited a gap between email authentication and identity verification that has been documented for years but rarely exploited at this level of polish. Researchers note that creating a mailbox inside a legitimate government domain is not the same as compromising that domain. In many cloud-hosted mail environments, subdomain delegation or contractor accounts can be provisioned by third parties under looser vetting than a primary agency administrator would expect. Once such an account exists, every email it sends inherits the parent domain’s SPF record and DKIM signature, which means a DMARC check at the receiving end will pass cleanly. The attacker therefore did not need to forge anything; they needed only to be allowed to exist on the infrastructure. That distinction is what made the Revolut Bitcoin data breach fake government request so difficult to detect in real time, and it is the part of the disclosure that compliance officers are likely to study most closely in the coming weeks.

Source: https://example.com

Leave a Comment

Your email address will not be published. Required fields are marked *