Newsroom
12 September, 2026 / News / AI / Tags: revolut, domain, agency, customer, email

Digital bank disclosed passports, addresses and full transaction histories, including Bitcoin activity, after an unauthorized request using an official agency domain passed its checks. No funds were lost
Revolut provided customer identity documents and financial records, including Bitcoin transaction histories, after receiving a request that appeared to originate from a government agency. The email came from an unauthorized account on the agency’s official domain and carried authentication credentials that cleared the company’s verification process. Revolut stated it acted under the belief the request was authentic.
The company later contacted the agency, confirmed the request was fraudulent, notified affected customers and regulators, and blocked the source. Customer funds remained secure throughout. The number of users involved has not been disclosed. On-chain investigator ZachXBT reported that multiple customers received alert emails on September 11 and described the episode as apparently limited in scope, possibly focused on high-net-worth individuals.
According to the customer notice, the disclosed material included full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers. Copies of identity documents such as passports or driver’s licences were provided, along with the selfies customers had submitted for verification. Revolut specified that biometric facial telemetry data was not included.
Account statements formed another category of data shared. These contained IBANs, account status, opening dates and Bitcoin wallet reference numbers. Withdrawal records and complete transaction histories, including Bitcoin activity, were also released. The notice does not indicate that private keys, passwords or full payment-card details formed part of the disclosure.
The categories listed represent information that may have been released; not every affected customer necessarily held every type of record. Revolut serves more than 80 million customers worldwide, though that figure refers to the overall customer base rather than those involved in this episode.
The request was sent directly from an unauthorized account using the agency’s official email domain rather than an address designed to resemble it. Revolut’s systems treated the message as legitimate because of the valid domain authentication. The notice does not state that an intruder gained access to Revolut’s internal systems, customer accounts or funds.
Potential consequences of such a personal-data disclosure can include identity theft, fraud and financial loss, according to guidance from the UK Information Commissioner’s Office. The office requires organizations to assess the information involved and the likely harm to individuals, and to report certain breaches within 72 hours where feasible. The customer notice does not confirm the precise timeline of Revolut’s discovery or regulatory notifications.
The episode occurred as Revolut continues to expand its digital-asset and banking services. The company has not publicly identified the specific government agency whose domain was used or provided further details on how the unauthorized sender obtained access to it.









