Did a Fake Government Email Cause the Revolut Data Leak?

4 hours ago 26
Revolut data leak

A fraudulent email carrying the digital fingerprint of a government agency was all it took to trigger one of the more unsettling fintech security stories of the year. According to on-chain investigator ZachXBT, the Revolut data leak exposed customer identity documents, banking records and Bitcoin transaction histories after the fintech giant mistook the forged request for a legitimate one and handed over sensitive user data to unauthorized parties.

Key takeaways

  • ZachXBT flagged the alleged breach on Telegram, sharing a Revolut customer notice describing the disclosure.
  • Revolut says the fraudulent request came from an unauthorized account using an official government agency’s actual email domain, which passed domain authentication checks.
  • Leaked data reportedly includes full names, dates of birth, occupations, addresses, ID documents, verification selfies, IBANs, account-opening dates, Bitcoin wallet reference numbers, withdrawal records and complete transaction histories.
  • The incident appears limited in scale so far, but ZachXBT says it may have specifically targeted high-net-worth individuals, some of whom have already received notification emails from Revolut.
  • Revolut says biometric facial telemetry data was not part of the disclosure, distinguishing it from the verification selfies that were leaked.

Reported Data Leak at Revolut Involving Sensitive User Information

The story surfaced on September 12, 2026, when ZachXBT posted an alert describing an alleged breach at Revolut. The investigator’s post, based on a customer notice sent by the company itself, painted a picture of a fintech platform that had been tricked, not hacked in the traditional sense — a distinction that matters enormously for how the incident should be understood.

Role of On-Chain Investigator ZachXBT

ZachXBT, known for tracking illicit crypto flows and exposing security failures across the industry, shared a screenshot of Revolut’s internal notice on Telegram. He noted that the overall number of affected accounts appeared limited at this stage but suggested the attack may have specifically targeted high-net-worth individuals. Several impacted users, he said, had already received official notification emails from Revolut confirming the disclosure.

Types of Data Compromised

The scope of what leaked is the part that should worry crypto users most. According to Revolut’s own notice, the compromised information includes full names, dates of birth, occupations, postal addresses, email addresses, telephone numbers, copies of identity documents such as passports or driver’s licences, and the verification selfies customers submitted during onboarding.

On the financial side, the disclosure reportedly covered IBANs, account status, account-opening dates, and Bitcoin wallet reference numbers embedded in account statements. Withdrawal records and complete transaction histories — including Bitcoin transfers — were also handed over. Revolut did draw one important line: it said biometric facial telemetry data, distinct from the selfie images themselves, was not part of what leaked.

Cause of the Data Breach: Fraudulent Government Information Request

At the heart of this cryptocurrency data breach sits a single deceptive email that exploited trust in official channels rather than any flaw in Revolut’s encryption or infrastructure. The company says it acted on what looked, by every technical measure, like a genuine government request.

How Revolut Mistook the Request as Legitimate

Revolut’s notice states plainly that the request carried valid domain authentication credentials, so the company fulfilled it “under the reasonable belief that it was an authentic government agency request.” That single sentence explains why this episode differs from a conventional hack: nobody breached Revolut’s systems or withdrew customer funds. Instead, the company disclosed the data itself, believing it was complying with a lawful order.

Use of Official Government Email Domain

What makes this case especially alarming is the method behind it. The unauthorized sender did not spoof a lookalike address — a common phishing trick — but instead sent the request directly from an account using the agency’s actual, official email domain. That allowed the message to pass domain authentication checks that would normally catch a forged sender. Revolut’s notice does not name the agency involved, nor does it explain how the unauthorized party gained access to that domain in the first place.

Impact and Scope of the Security Breach

So far, the fallout looks contained but far from trivial. Revolut’s disclosure did not involve account takeovers or fund withdrawals, yet the type of data exposed is exactly what fraudsters need to build convincing identity-theft schemes or targeted social-engineering attacks against wealthy clients.

Unauthorized Data Access and User Notification

ZachXBT reported that multiple customers received alert emails from Revolut on September 11, though neither he nor the portion of the notice he shared gave a confirmed total count of affected users. Revolut operates at massive scale — the company has said it serves more than 80 million customers globally — but that figure describes the overall size of its business, not the number caught up in this particular disclosure.

Targeting of High-Net-Worth Individuals

ZachXBT’s assessment that the breach may have specifically targeted high-net-worth individuals has not been independently confirmed by Revolut in the material made public. Still, the combination of identity documents, IBANs, and full Bitcoin transaction histories is precisely the kind of dossier that would let a bad actor identify who among Revolut’s user base holds significant crypto or fiat wealth.

Potential Risks to Affected Users

Why this matters goes beyond one company’s internal error. When identity documents and transaction records land in the same leaked file, whoever receives them gets a detailed financial profile of a real person — enough, in theory, to attempt fraud, impersonation, or highly personalized phishing. This is what separates a high-net-worth data leak from a routine breach: the value of the target amplifies the risk of the exposure.

There’s also a regulatory dimension. Data protection guidance generally requires companies to report certain personal data breaches within 72 hours of becoming aware of them and to notify affected individuals without undue delay when the risk to their rights is high. Revolut’s notice does not indicate whether a regulator has been informed or when the company first discovered the fraudulent request.

The episode lands at an awkward moment for Revolut, which has spent recent weeks pushing deeper into crypto and banking. The company launched its euro-backed EURR stablecoin to select customers in Denmark, Poland, and Portugal in late August, and it secured conditional approval from the Office of the Comptroller of the Currency on September 3 for a proposed U.S. bank in Stamford, Connecticut. Neither expansion is connected to the leak, but both underscore how much sensitive financial data — including crypto holdings — now flows through Revolut’s systems as it scales globally.

This case also illustrates a broader vulnerability that goes well beyond one company: fraudulent data requests that mimic real government channels can bypass even legitimate authentication systems, because the weak point isn’t cryptographic — it’s institutional trust. Any platform that responds to law-enforcement or regulatory requests, crypto exchange or bank alike, faces the same exposure if it can’t independently verify who is really asking.

FAQ

Who reported the Revolut data leak?

On-chain investigator ZachXBT reported the alleged data leak involving Revolut, sharing a copy of the company’s own customer notice on Telegram.

What caused the data leak at Revolut?

Revolut says it mistakenly treated a fraudulent government information request as legitimate because the email carried valid domain authentication credentials from an official government agency domain, leading the company to disclose customer data to unauthorized parties.

What types of user data were compromised in the leak?

The leaked data reportedly includes full names, dates of birth, occupations, contact details, identity documents, verification selfies, IBANs, account-opening dates, Bitcoin wallet reference numbers, withdrawal records, and full transaction histories including Bitcoin transfers.

Who was likely targeted in the Revolut data breach?

The breach appears to affect a limited number of accounts so far, and ZachXBT believes it may have specifically targeted high-net-worth individuals, some of whom have already received official notification emails from Revolut.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article