The incident was not a system breach, but it once again exposed the risks of KYC data within the encrypted user community.
Written by: Boaz Sobrado, Forbes
Translated by: AididiaoJP, Foresight News
UK fintech company Revolut confirmed that it recently submitted some customer identity data and transaction records to a third party posing as government officials due to a misleading email disguised as a government request. This incident did not involve a system being hacked, nor is there evidence that customer accounts were accessed by others; Revolut proactively sent the information during the "government request" process.
From around September 11, 2026, affected customers began to receive notifications. Former Mt. Gox CEO Mark Karpelès publicly released the email he received, titled "Urgent Security Update About Your Revolut Account." On-chain investigator ZachXBT subsequently shared related content in a Telegram channel, stating that the affected scope seems limited, targeting high-net-worth individuals more specifically.
It was disclosed that the email in question was sent from a legitimate government agency's domain and held valid domain authentication certificates, passing SPF, DKIM, and DMARC checks. For banks and licensed payment institutions, these technical checks are typically used to determine if an email was indeed sent by that institution. As a result, Revolut treated it as a legitimate law enforcement or regulatory request and submitted the information. The company only discovered that the email address did not belong to any authorized personnel when verifying with the government agency afterward.
Revolut immediately blocked the address internally and reported to the relevant government agencies, police, and data protection and financial regulatory departments, while notifying affected customers. A spokesperson told the media that this was a "complex external impersonation scam" and emphasized that "Revolut's systems and customer funds were not affected." The company did not disclose the name of the impersonated agency or the exact number of affected individuals or market scope, only stating that "limited customers" had been directly contacted.
The potentially leaked information listed in the notification is much more comprehensive than typical password leaks. Identity information includes full name, date of birth, and occupation; contact information includes address, email, and phone number; document information includes photocopies of passports or driver's licenses, as well as facial verification selfies submitted when opening the account. The company specifically stated that the biometric template used for comparison (facial telemetry) was not disclosed, but the original selfie was included. Financial information includes account statements, IBAN, account status, account opening date, internal wallet reference number, and complete transaction records, clearly containing records of Bitcoin trading and withdrawals. Currently, there are no signs that private keys, login passwords, card PINs, or account balances were also submitted, nor are there any public reports of stolen funds.
For encrypted users, the danger of this data lies not in the immediate theft of funds, but in the potential for on-chain activities to be directly linked to real identities. Passport photos, addresses, IBANs, combined with complete in-and-out records and wallet reference numbers, are sufficient for targeted phishing, impersonating customer service to carry out account recovery, or conducting reverse on-chain analysis from real names. ZachXBT warns that leaked lists and addresses have previously been associated with offline harm incidents targeting holders.
Revolut characterized this incident as external impersonation, rather than a production system breach. Based on existing publicly available materials, the attackers exploited the regulatory requirement for financial institutions to respond to government requests: the email was from a legitimate domain, authentication checks were passed, and internal reviews were handled as though they were real requests. Karpelès and others publicly called on the company or the impersonated agency to disclose the name of the agency, so that other banks and exchanges could trace the same email back. As of the time of publication, no relevant parties have named names.
It is important to distinguish that Revolut's past incidents are different from this one. In 2022, Lithuania's data protection agency recorded that about 50,150 customers were affected by a social engineering attack targeting employees; in July 2026, a black market claimed to have sold 75 million Revolut records, which the company internally verified to be more likely a forgery; in February of the same year, the company had reported to law enforcement regarding a former employee suspected of extorting KYC data. These do not belong to the same incident as this "fake government email request."
For customers who have received notifications, the most realistic risk is secondary fraud. With passport photos, addresses, and transaction details in hand, criminals can easily send another "official follow-up" email or call requesting verification codes, recovery phrases, or to transfer cryptocurrency to a so-called "secure wallet." Revolut's advice remains: communicate only through in-app chat, do not click on unfamiliar links, and do not answer sudden calls mentioning this leak.
There are still several questions to clarify: exactly how many people were submitted data, which country's agency was involved, what day the request was made, what day the data was sent, whether the same email address had previously initiated requests to other licensed institutions, and whether the third party continued to use the information after obtaining it. If these blanks cannot be filled, other platforms will find it difficult to conduct targeted investigations.
This incident once again presents an ongoing issue: regulatory demands require platforms to collect passports, selfies, and complete transaction histories, and once these files are deceived away by seemingly "legitimate requests," the harm is often more difficult to resolve than a typical credential stuffing attack. The system has not been breached, the funds remain in the accounts, but the information that has linked customers' real identities to Bitcoin transaction histories has already leaked out.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。