Someone emailed Revolut from a government-looking address. It worked.
A fake request sent from a domain that looked official was enough to pull customer ID documents and Bitcoin transaction history out of Revolut. No hacking required — just a convincing email address.
Revolut says customer data was exposed after the company received a fake request that came from a government domain. The data included KYC material — the passport or ID photos and personal details you hand over when you open an account — and Bitcoin transaction data.
There was no break-in, no stolen password, no clever code. Somebody asked, the request looked official, and the answer came back. Onchain investigator ZachXBT speculated that the incident may have been targeting high-net-worth users.
Think about what that combination actually is. Your ID document tells someone your face, your legal name and where you live. Your Bitcoin transaction history tells them roughly what you have. Separately, each is uncomfortable. Together, they are a shopping list: here is a person, here is their address, here is how much they hold. That is the pairing that matters, and that is why ZachXBT's guess about wealthy users is the part worth sitting with.
The uncomfortable bit isn't the technology. It's the trust chain. Banks and exchanges are built to answer official requests quickly — that is the whole point of an official request. Which means the weakest link is not encryption, it's whoever checks that the sender is who they say they are.
A door that opens for the police also opens for anyone who looks like the police.
Anyone who uploaded a passport photo to a finance app and never thought about it again — which is most people under 40 who have ever opened an account on a phone. That includes the 25-year-old with a first salary, a rented flat and maybe a couple of thousand in crypto: they assume the risk is their password, and it isn't. And it includes the people ZachXBT thinks were the actual target — customers holding enough that someone would build a fake government domain specifically to find them.
Revolut has said the KYC and Bitcoin transaction data was exposed after the fake request. Beyond that, the source does not say how many customers were affected, who sent the request, or whether any authority is looking into it. We don't know, and we would rather say so than guess. The thing to watch is whether Revolut puts a number on it — and whether affected customers get told individually or read about it in the news.
You can change a password in ten seconds. You cannot change your passport photo, your face, or the fact that a specific wallet is now linked to your name. Some leaks expire. This kind doesn't.
Sources: The Block, «Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov't domain», 12 September 2026.
Мошенники получили паспортные данные и историю биткоин-переводов клиентов Revolut, просто прислав запрос с адреса, похожего на государственный, — и это удар по тем, у кого на счетах больше всего.
Written by THE TELL’s AI newsroom. how we work · corrections