Revolut says attacker used a real government email domain to pry customer KYC and Bitcoin transaction data loose
Revolut says an attacker used a legitimate government agency email domain to submit fraudulent data requests, exposing affected customers' KYC documents and full transaction histories, including Bitcoin activity.
Revolut has told customers that an unauthorized third party obtained sensitive account information by submitting fraudulent requests from an email account on a legitimate government agency's domain, according to The Block, which cited disclosures Revolut made to TechCrunch on Saturday.
A Revolut spokesperson called it a "sophisticated external impersonation scam," told The Block the company blocked the email address once it was identified, and said its systems and customer funds were unaffected. Revolut said a "limited number" of customers were hit and that it contacted them directly; some reported receiving notices on Friday. The company declined to say how many people were affected, whether the incident was confined to one market, or which agency's domain was abused.
Per a notification reproduced by The Block, the exposed data may have included names, dates of birth, postal and email addresses, phone numbers, and copies of identity documents such as passports and driver's licenses, along with verification selfies, account statements and transaction histories. Former Mt. Gox CEO Mark Karpelès, who said he was among those affected, publicly shared a copy of Revolut's notice; it stated that account statements, IBANs, withdrawal records and full transaction histories — including Bitcoin transactions — were potentially handed to the unauthorized party. Revolut said it alerted the relevant agency, law enforcement, data protection authorities and financial regulators.
On-chain investigator ZachXBT flagged the breach to followers: "While the incident is likely limited in size it seems to have been targeted at high net worth users."
Key facts
- Attacker used an email on a legitimate government agency domain to submit fraudulent requests for customer records (Revolut, via The Block/TechCrunch, Sept. 12, 2026).
- Potentially exposed: names, DOBs, addresses, phone numbers, passports/licenses, selfies, account statements, IBANs, withdrawal records and full transaction histories including Bitcoin (Revolut notice, shared by Mark Karpelès).
- Revolut says funds and systems unaffected, a "limited number" of customers hit; declined to give a count, market or agency (Revolut spokesperson, via The Block).
- ZachXBT speculated the attack targeted high-net-worth users (ZachXBT).
The real-world read
Read the company's framing carefully. "Funds and systems unaffected" is likely true and also beside the point: what leaked is the exact package an identity thief or extortionist wants — government ID, selfies, home address and a complete record of someone's money movements. Calling it "limited" while refusing to give any number, market or the name of the impersonated agency leaves the actual scope unverifiable. The attack vector — abusing a trusted domain to look legitimate — mirrors a breach Trezor disclosed the same week, where a compromised third-party email provider let phishing go out from Trezor's own domain, and follows recent exposures at SafePal (~39,798 customers) and at Trezor's shipping vendor ShipMonk (~67,000 U.S. customers), per The Block. The timing is awkward: Revolut won conditional U.S. national-bank approval from the OCC earlier this month and is pushing its EURR stablecoin and crypto arm.
This is reporting, not financial advice.
Sources
- The Block (Tier 2, secondary) — primary account of the incident, Revolut's statements, the customer notice, and context on Revolut's expansion and the wider string of breaches; itself cited TechCrunch for Revolut's Saturday disclosure. Not marketing.
- Revolut customer notice, shared publicly by Mark Karpelès (affected customer) — specifics on exposed data, including IBANs and Bitcoin transaction histories.
- ZachXBT (on-chain investigator) — attributed speculation that the attack targeted high-net-worth users; his read, not confirmed fact.