Revolut Handed Customers’ Passports and Bitcoin Records to a Fake Government Request. Are You Affected?

Someone impersonated a government agency and tricked Revolut into handing over customer passports, Bitcoin records, and full account histories without breaking a single line of code. If you hold crypto on Revolut, here is what the attacker now knows about…

Published September 12, 2026, 8:26am ET · 4 min read

This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.

Modern glass skyscrapers in the London financial district rise across the River Thames representing contemporary urban architecture and a dynamic business city skyline.
© Surachet Jo / Shutterstock.com

Revolut, the London-based digital bank with more than 60 million customers worldwide, handed a bundle of customer files to someone impersonating a government agency. The request arrived from an official-looking email domain, and Revolut’s compliance team treated it as genuine and released the records. On-chain investigator ZachXBT disclosed the incident, and Revolut has sent security notices to the customers whose data went out in the response.

The bank’s system wasn’t compromised, so no customer money was laundered. What failed was the check on whether the request was real, which is a different problem from an intrusion and, in some ways, a harder one to close. The exposed set includes Bitcoin (CRYPTO:BTC) transaction histories alongside government ID and full account records, which is exactly the raw material a competent phisher wants. So who’s on the list, and how would you know?

Revolut Complied With a Spoofed Government Request

A hand holds a virtual bank surrounded by arrows and percentage signs, symbolizing rising interest rates and banking growth trends.

Pingingz / Shutterstock.com

A request arrived at Revolut that presented itself as a lawful government demand for customer records, and Revolut’s team treated it as real and answered it. A spoofed domain is one built to imitate a real institution’s address closely enough to pass a human check, and the sender used one. Whoever wrote it knew the format banks expect when law enforcement asks for account data, and knew which specific customers to ask about.

The files that went out cover almost everything a bank holds on a customer. Passports and driver’s licenses, KYC selfies, account statements, IBANs, withdrawal records, and Bitcoin transaction histories all left in the response. KYC, or Know Your Customer, is the identity check a regulated bank runs at signup and stores for the life of the account, which is why the selfie in the file matches the photo page of the passport under the same name.

The failure was authentication of the sender. Revolut’s systems weren’t broken into. A human process, or a partly automated one, decided the request was genuine and released the records. That’s harder to fix than a software bug because it depends on how staff verifies a counterparty under legal-request pressure, and every large bank that handles government demands faces the same problem in some form.

Revolut was Tricked Into Releasing Customers’ Data

A close-up of hands holding a glowing smartphone, surrounded by numerous blue square icons representing digital financial services. Icons include a wallet, QR code, bank, credit card, pie chart, a 'BUY' button, money stacks, a money bag, a dollar bill, a computer with a piggy bank, NFC, currency exchange symbols, and a smartwatch with a WiFi symbol. The background is blurred, depicting a modern digital environment.

Summit Art Creations / Shutterstock.com

What Revolut handed over was a document set, sent by the bank in response to what looked like a normal legal request. The attacker never touched a balance and never held a login credential. What Revolut handed over was a document set, sent by the bank itself in response to what looked like a normal legal request.

A file that names a customer, their home address, their ID photos, their bank flow, and their Bitcoin history is the raw material of a convincing phishing attack. Phishing is a message engineered to look like it comes from someone you trust, so the attacker can extract a password, a two-factor code, or a signed crypto transaction.

A Bitcoin transaction history is more dangerous than a bank statement, because the coins on chain are still there and still yours. A message that quotes your last on-chain withdrawal, the address it went to, and the exact amount reads as if it came from your exchange, and a reader who would never click a generic scam might click this one. Physical risk rises too when an attacker knows both a home address and a rough wallet size.

High-Net-Worth Accounts Look Like the Target

Businessman working on finance and accounting reports with calculator and growth chart, representing business financing, banking, investment, and financial management strategy

Father - Studio / Shutterstock.com

The exposed set looks limited and targeted at high-net-worth accounts, and affected users received security notices from Revolut. That pattern fits an attacker who chose which customers to ask about, rather than one who scraped whatever they could reach. Revolut hasn’t published a full recap, so the total number of affected accounts, the criteria used to pick them, and the internal path the request took aren’t public.

If you’re in that group, the first sign will probably be an email, a phone call or a chat message that already knows details only your bank should know. The contact might reference a recent transfer, quote your IBAN, cite your passport number, or name a Bitcoin address that received a withdrawal from your Revolut wallet. A caller who recites those specifics without prompting is the scenario this file enables, and the correct response is to hang up and open the Revolut app to verify.

Are You Affected?

You’re likely affected if Revolut sent you a security notice, because the bank is contacting people on the list one by one rather than issuing a general disclosure. If you hold a large balance, use Revolut for crypto withdrawals, or completed enhanced KYC as a premium or private customer, you fit the profile the targeting suggests so far. The notice from Revolut is the only definitive confirmation you’ll get, and the absence of one is a reassuring sign without being a guarantee.

What would change the picture is a full recap from Revolut naming the number of accounts affected, the date range of the request, and the internal approval path that let it through, because those specifics decide how widely the phishing risk actually spreads. Until that recap arrives, the answer to whether you’re affected is the one in your inbox. If a notice from Revolut arrived there, treat every unsolicited contact that quotes your account details as hostile until you’ve verified it through the app.

Contact [email protected] for any questions or corrections.

Sam Daodu

Sam Daodu is a crypto analyst who's spent nearly a decade making blockchain understandable—no easy task when most whitepapers read like fever dreams. He writes for 24/7 Wall St., covering Bitcoin, altcoins, and crypto market analysis for investors. Before crypto, he was a tech writer (back when explaining "the cloud" was peak innovation). Since 2018, he's written for CoinTelegraph, Yahoo Finance, The Block, Cryptonews, Zypto, Rain, and more—basically anywhere people want crypto news without the headache. Sam runs MacLabs Marketing, a content agency for crypto brands tired of sounding like AI wrote their website. He also publishes free crypto education on his site for Web3 enthusiasts who think "gas fees" is a typo. When he's not writing or staring at charts, Sam's either: - Watching anime (currently convinced One Piece has better tokenomics than most altcoins) - At the gym sculpting himself into a Greek god - Listening to the music your mum warned you only bad boys listen to Connect: LinkedIn | Email | MacLabs Marketing

All articles →