security-privacy · Revolut · security · privacy · KYC · Bitcoin

Revolut Discloses Customer Data Exposure Through Fraudulent Government Requests

A limited number of customers had identity, account and Bitcoin transaction information disclosed after requests arrived through a legitimate government email domain. Revolut says its systems and customer funds were unaffected.

Observed September 13, 2026 at 8:05 PMBlue Rogues Newsroom
Revolut Discloses Customer Data Exposure Through Fraudulent Government Requests — Blue Rogues Crypto editorial artwork
Blue Rogues editorial artwork · BRC-20260913-001

Revolut says an unauthorized third party used an email account on a legitimate government agency domain to submit fraudulent requests for customer records.

According to the company account reported by The Block, the information potentially disclosed included names, dates of birth, contact details, identity-document copies, verification selfies, account statements, withdrawal records and full transaction histories, including Bitcoin transactions.

The distinction is critical: this was an exposure of identity and financial-history data through a trusted request channel. Revolut said its systems and customer funds were not compromised, and there is no evidence in the disclosure that customer wallets or private keys were accessed.

Revolut described the affected group as limited but did not disclose a customer count, the government agency involved or whether the incident was confined to one market. The company said it blocked the address, contacted affected customers and notified the relevant agency, law enforcement, data-protection authorities and financial regulators.

The operational question now is whether financial institutions strengthen out-of-band verification for sensitive records requests. Valid control of an official email domain is not, by itself, proof that a particular request is legitimate.

Sources and disclosures

Source: The Block, September 12, 2026, citing Revolut and a notice sent to affected customers. Customer count, agency identity and geographic scope remain undisclosed.

Update note

Observed September 13, 2026 at 20:05 BRT. This report describes a data-disclosure incident, not a wallet breach or loss of customer funds.