TL;DR
▶ Revolut confirmed on September 12, 2026 that it disclosed passports, selfies, IBANs, and full Bitcoin transaction histories to an unauthorized third party who impersonated a government agency.
▶ The fake request used a legitimate government domain email that passed SPF, DKIM, and DMARC authentication checks. Revolut’s compliance team treated it as genuine and fulfilled it.
▶ Revolut only discovered the fraud by independently contacting the government agency after the fact, at which point the agency confirmed it had not made the request.
▶ Former Mt. Gox CEO Mark Karpeles and Aave founder Marc Zeller both publicly confirmed they were among those affected.
▶ ZachXBT assessed the incident as targeted at high net worth users. Revolut has not confirmed the number of victims, the agency involved, or the specific market.
▶ No customer funds were lost. Biometric facial telemetry was not exposed. But the data package that was handed over is a complete fraud toolkit: legal identity, home address, and on-chain Bitcoin wallet history.
Revolut confirmed on September 12, 2026 that it handed sensitive customer data to an unauthorized third party after being deceived by a fraudulent government information request. The request came from an email account operating inside a legitimate government agency’s domain infrastructure, carrying valid authentication credentials that passed Revolut’s automated security checks. Revolut’s compliance team, acting on the reasonable belief that the request was genuine, fulfilled it.
What went out the door: full names, dates of birth, occupations, home addresses, email addresses, phone numbers, copies of passports and driver’s licences, identity verification selfies, IBANs, account statements, withdrawal records, and complete transaction histories including Bitcoin. Biometric facial telemetry was confirmed secure. Customer funds were unaffected.
Revolut discovered the fraud not through any internal detection system but by separately contacting the government agency to verify the request, at which point the agency confirmed it had sent nothing. The company then blocked the email address and notified affected customers, law enforcement, data protection authorities, and financial regulators. It has not publicly named the government agency, the number of affected customers, or the specific market. Former Mt. Gox CEO Mark Karpeles publicly confirmed he was among those affected after posting excerpts of Revolut’s customer notification on X.
What Is a Fake Government Data Request and How Did This One Pass Every Check?
What is a legitimate government data request?
Financial institutions including banks, fintechs, and crypto platforms are legally required to respond to lawful requests for customer information from government agencies, typically law enforcement or regulatory bodies. These requests, also called legal process requests or emergency data requests (EDRs), ask for KYC records, transaction histories, and account details about specific customers. Institutions verify the request came from a genuine agency by checking the email domain and authentication credentials. The entire security model depends on the email being what it claims to be.
The attack exploited a specific gap in how email authentication works. When a financial institution receives what appears to be a government request, it checks three standard email authentication protocols: SPF (Sender Policy Framework) verifies the sending server is authorised to send on behalf of the domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature verifying the email was not modified in transit. DMARC (Domain-based Message Authentication, Reporting and Conformance) tells recipients what to do when SPF and DKIM checks fail.
In this case, all three checks passed. The attacker did not spoof the domain from outside. The attacker either created an unauthorized account directly inside the government agency’s email domain infrastructure or compromised an existing account within that infrastructure. Revolut’s own customer notification, excerpts of which were published by Mark Karpeles, stated: “The request originated from an unauthorised email account created directly within the official government agency’s email domain.” The email was technically authentic in every measurable way. The account sending it was not authorized to do so.
This is the critical distinction that makes the Revolut incident harder to dismiss than a typical phishing attack. Revolut was not tricked by a lookalike domain, a typosquat, or a spoofed header. The email passed every automated authentication check because it originated from inside the real domain. The failure was not in Revolut’s technical controls. It was in the assumption that a technically authentic email from a government domain represents an authorized government request. Those two things are not the same thing, and the entire financial industry’s legal request process is built on that assumption.
Exactly What Data Was Exposed: The Full List
Data Exposed in the Revolut Fake Government Request Incident
Source: Revolut customer notification reviewed by TechCrunch, Mark Karpeles X post, BNO News | @cryptonewsbytes
| Data Category | Specific Items | Exposure Status |
|---|---|---|
| Identity documents | Passport copies, driver’s licence copies | EXPOSED |
| Biometric verification | Identity verification selfies (facial photos taken during KYC) | EXPOSED |
| Biometric telemetry | Facial recognition telemetry data | SECURE (not exposed) |
| Personal details | Full name, date of birth, occupation, home address, email, phone number | EXPOSED |
| Banking details | IBAN, account opening date, account status, wallet reference numbers | EXPOSED |
| Financial records | Account statements, full withdrawal records | EXPOSED |
| Crypto transaction history | Complete transaction history including Bitcoin transactions, wallet references | EXPOSED |
Source: Revolut customer notification reviewed by TechCrunch and shared in excerpts by Mark Karpeles on X, September 12 2026. Customer funds and system access: unaffected. | @cryptonewsbytes
Why Bitcoin Transaction History in a KYC Data Breach Is a Specific Danger
Most data breach analyses focus on identity risk: a stolen passport enables identity fraud, a stolen home address enables physical targeting. Both apply here. But the exposure of full Bitcoin transaction histories alongside a legal identity creates a threat vector that is specific to crypto holders and more dangerous than either element alone.
A Bitcoin transaction history shows every wallet address that ever sent to or received from the victim’s Revolut account. Blockchain analytics firms and sophisticated criminals can trace those transactions forward and backward across the chain to map the victim’s broader holdings and financial relationships. If the victim ever moved Bitcoin from Revolut to a hardware wallet, the receiving address appears in the transaction history. If the attacker can correlate that address with other blockchain activity, they can estimate the victim’s total holdings well beyond what was held at Revolut.
Combined with a home address and a passport, this creates the raw material for a wrench attack: a physical attack at the victim’s home using the threat of violence to force transfer of crypto assets. Wrench attacks against high-net-worth crypto holders have been a documented and growing threat across 2025 and 2026. ZachXBT’s assessment that the incident appeared targeted at high-net-worth users is precisely what makes the Bitcoin transaction history exposure the most dangerous element of the data package.
What is a wrench attack?
A wrench attack is a physical assault or kidnapping where the attacker uses violence or the threat of violence to force a crypto holder to transfer their assets. Unlike exchange hacks or phishing attacks, wrench attacks target the person rather than the technology. The name comes from the principle that even the strongest cryptographic protection can be defeated by threatening someone with a $5 wrench. The exposed data from the Revolut incident, specifically a home address paired with a Bitcoin transaction history showing significant holdings, is exactly the targeting package a wrench attack requires. Affected users with material Bitcoin holdings should take the physical security risk seriously.
Who Was Affected: What Mark Karpeles and Marc Zeller Confirmed
The Revolut customer notification began circulating on September 11, 2026. Two notable names publicly confirmed they were among those affected. Mark Karpeles, the former CEO of Mt. Gox, the Bitcoin exchange that collapsed in 2014 after approximately 850,000 Bitcoin were stolen, posted substantial excerpts of Revolut’s customer notification on X at 07:06 UTC on September 12, confirming he received it. His post was the first major public confirmation of the incident and is the primary source for the specific data categories listed in the notification.
Marc Zeller, founder of the Aave Chan Initiative and a significant figure in the Aave DeFi governance ecosystem, also confirmed he was affected. Zeller noted on X that the incident occurred shortly after Revolut had sent him a separate email requesting a significant amount of additional personal data, threatening account closure within 20 days if he did not comply. His experience suggests the fraudulent request may have been targeted in part at users who were already in data-sharing interactions with Revolut.
ZachXBT, the on-chain investigator who has been responsible for identifying multiple significant crypto fraud cases in 2026, circulated the customer notice on his Telegram channel on Friday September 12 and assessed that the incident appeared limited in scale and targeted at high net worth users. ZachXBT’s read of “high net worth” is consistent with the nature of the data targeted: full Bitcoin transaction histories and IBANs are most valuable as targeting intelligence against users with significant holdings. Revolut has 60 million customers globally. The data package would be far more valuable to a targeted attacker than a mass-market operation.
What Revolut Has and Has Not Disclosed
As of September 12, 2026, Revolut has confirmed the following: a fraudulent request was submitted using a legitimate government agency domain email that passed authentication checks; the company fulfilled the request believing it genuine; it discovered the fraud by independently contacting the agency; it blocked the email address and notified affected customers, law enforcement, data protection authorities, and financial regulators. A Revolut spokesperson confirmed: Revolut systems and customer funds are unaffected.
Revolut has declined to disclose: the identity of the government agency involved; the number of affected customers; whether the incident was limited to a specific market or country; the timeline of when the fraudulent request was made relative to when it was discovered; whether the stolen data has been observed in use elsewhere. Each of these omissions has a different implication.
The failure to name the government agency is the most consequential gap in the public record. Naming the agency would allow every other regulated financial institution to search its own legal-request logs for messages from the same domain. If the same attacker sent fraudulent requests to other fintechs and banks using the same compromised government email infrastructure, those institutions cannot identify and assess their own exposure without knowing which domain was involved. Revolut’s silence on this point protects the ongoing investigation but creates a systemic risk gap for the broader industry. SecurityAffairs made this observation directly in its coverage.
The Emergency Data Request Attack Vector: Why This Is Not Isolated
The mechanism used in the Revolut attack, gaining access to or creating an unauthorized account within a legitimate government domain and using it to submit fraudulent legal process requests, is not new. It has been documented in the United States context through multiple cases involving law enforcement impersonation to extract data from technology companies.
In the US, the FBI’s Internet Crime Complaint Center has documented emergency data request fraud as an increasing threat since 2023. The general pattern: an attacker compromises a government email account or creates a fraudulent one within an authentic domain, then submits an “emergency” data request to a technology company or financial institution, bypassing normal legal process review timelines by claiming imminent harm. The target company, seeing a request from what appears to be a legitimate government email address, complies under its legal obligation to respond to lawful requests.
Several high-profile US technology companies including Apple and Meta received fraudulent emergency data requests in 2022 from attackers using compromised law enforcement email accounts. The Revolut incident follows the same pattern applied to a regulated financial institution with 60 million customers holding comprehensive KYC and transaction data. The difference is that financial institution data includes complete identity verification packages and detailed transaction histories that are more operationally valuable for targeted fraud than the contact information typically sought from tech companies.
What should other fintechs and banks do right now?
The Revolut incident reveals a systemic gap in how financial institutions verify legal process requests. Standard authentication checks, SPF, DKIM, DMARC, are necessary but insufficient when the attacker operates from inside an authentic domain rather than outside it. Best practice responses include: telephone verification to a known number at the requesting agency before fulfilling any sensitive data request; requiring formal letterhead on a separate secure channel alongside email; implementing a time delay between receiving and fulfilling requests to allow verification; and checking the requesting individual’s name against a known contact list at the agency. None of these are foolproof. All of them add friction that reduces the success rate of this attack vector.
What Affected Revolut Customers Should Do Right Now
If You Received the Revolut Notification: Action Checklist
Assume your identity documents are in hostile hands
If you received a Revolut notification about this incident, treat your passport and driver’s licence as compromised. Consider applying for replacements and flag the compromise to your national identity authority if that mechanism exists in your jurisdiction.
Alert your bank and any other financial institutions
Your IBAN and account details are now known to the attacker. Alert your bank’s fraud department. Monitor all accounts for unauthorised access attempts, unusual transactions, or requests to change contact details or access credentials.
Treat your home address as exposed
Physical security risk is real for holders of significant Bitcoin. If your transaction history shows material holdings, assess whether your home address and daily movements need to be treated more carefully. ZachXBT’s assessment of targeting at high-net-worth users is the relevant context here.
Map your Bitcoin exposure
Review what your Revolut transaction history shows. If it includes transactions to external wallets, consider whether those wallets are now linkable to your legal identity through blockchain analytics. Significant holdings in those downstream wallets represent elevated risk.
Be alert to follow-on fraud attempts
Your phone number, email, and home address are exposed. Expect an increase in targeted phishing, vishing, and SMS fraud using your real name and account details to appear credible. Do not provide 2FA codes, passwords, or seed phrases to anyone regardless of what they claim to know about you.
Watch for SIM swap attempts
Your phone number is exposed. SIM swap attacks, where an attacker transfers your phone number to a SIM they control to intercept 2FA codes, are a documented follow-on to data breaches involving phone numbers. Contact your mobile carrier to add a PIN or verbal password requirement for SIM changes.
Not legal or financial advice. Consult a security professional if your holdings are material. | @cryptonewsbytes
Frequently Asked Questions
What happened in the Revolut data breach?
Revolut confirmed on September 12, 2026 that it handed sensitive customer data to an unauthorized third party after receiving a fraudulent information request that appeared to come from a legitimate government agency. The request used an email account operating inside an actual government agency’s domain and passed all standard authentication checks (SPF, DKIM, DMARC). Revolut fulfilled the request believing it was genuine and only discovered the fraud by independently contacting the agency afterward.
What data did Revolut expose?
The exposed data included: full names, dates of birth, occupations, home addresses, email addresses, phone numbers, copies of passports and driver’s licences, identity verification selfies, IBANs, account statements, withdrawal records, and complete transaction histories including Bitcoin transactions. Biometric facial telemetry was confirmed secure. Customer funds were not affected.
How many Revolut customers were affected?
Revolut has not disclosed the number of affected customers. The company said a ‘limited number’ were impacted and that those customers were contacted directly. ZachXBT assessed the incident as limited in scale and potentially targeted at high-net-worth users, though Revolut has not confirmed this.
Which government agency was involved?
Revolut has declined to name the government agency whose domain was used in the attack, citing a live investigation. It has also not disclosed whether the incident was limited to a specific country or market. The lack of public disclosure about the agency is a gap that prevents other financial institutions from checking their own legal-request logs for similar fraudulent requests from the same source.
Were Revolut customer funds lost?
No. Revolut has confirmed that customer funds and systems are unaffected. The incident involved the disclosure of customer data rather than any direct access to accounts or theft of funds. The risk from the breach is follow-on fraud enabled by the exposed data, not immediate financial loss.
What is a fake government data request attack?
A fake government data request attack, also called an emergency data request fraud, involves an attacker gaining access to or creating an account within a legitimate government agency’s email domain, then using that account to submit fraudulent information requests to financial institutions or technology companies. The target company sees the request coming from what appears to be an authentic government email and complies under its legal obligation to respond to lawful government requests. SPF, DKIM, and DMARC authentication checks pass because the email originates from inside the real domain.
What should I do if I received the Revolut data breach notification?
Treat your identity documents as compromised and consider applying for replacements. Alert your bank’s fraud department. Enable additional security on your mobile account to prevent SIM swaps. Monitor all accounts for unusual activity. Be alert to targeted phishing and vishing calls that use your real name and account details. If you hold significant Bitcoin, be aware that your transaction history and home address are now potentially linked in the attacker’s data and assess your physical security accordingly.
Further Reading
The Hacken Q2 2026 report that categorises operational failures as the dominant crypto loss vector. The Revolut incident is a textbook operational failure: not a system breach, but a process failure in verifying legal requests.
The July 21 DOJ seizure covering organised crypto fraud networks. The same networks that run romance scams and pig butchering operations also conduct targeted data acquisition campaigns to identify high-value crypto holders.
Sources: TechCrunch September 12 2026 (primary: Revolut confirms customer data breach through fake government requests), The Block September 12 2026 (primary: Revolut says customer KYC, Bitcoin transaction data exposed), BNO News September 12 2026 (primary: Revolut shared sensitive customer data after fake government request), CryptoTimes September 12 2026 (SPF DKIM DMARC analysis and Karpeles timeline), SecurityAffairs September 12 2026 (systemic risk assessment), ZachXBT Telegram September 12 2026, Mark Karpeles X post @MagicalTux September 12 2026 (primary customer notification excerpts) | Published September 12, 2026 | CryptoNewsBytes.com | Not financial advice.

