Close Menu
Crypto Valley Journal
    Facebook X (Twitter) Instagram
    Crypto Valley Journal
    • Hot Topics
      • News
      • Minds
    • Focus
      • Background
      • Blockchain
      • Legal & Compliance
      • Non-Fungible Token (NFTs)
    • Investing
      • Markets
      • Financial Products
      • Decentralized Finance (DeFi)
      • Exchange overview
    • Education
      • Basics
      • Glossary
      • Politicians on crypto
    • Statistics
      • Bitcoin-ETF-Flows
      • Ethereum-ETF-Flows
      • Crypto market data
      • On-chain data
    • Academy
      • Overview
      • Part 1: Blockchain
      • Part 2: Money
      • Part 3: Bitcoin
      • Part 4: Cryptocurrencies
      • Part 5: Decentralized Finance
      • Part 6: Investing
    • English
      • Deutsch
    Crypto Valley Journal
    You are at:Home » Hot Topics » News » Revolut confirms data breach after fake government request
    The Revolut data breach exposed ID copies, verification selfies and complete Bitcoin transaction histories to an unknown third party.

    Revolut confirms data breach after fake government request

    By Editorial Office CVJ.CH on 14. September 2026 News

    Revolut has confirmed a data breach after an unknown third party filed a fraudulent information request. The attacker used the email account of a genuine government domain to obtain ID copies and complete Bitcoin transaction histories.

    Revolut is a British digital bank. Its app bundles accounts, payments, securities trading and crypto services in one place. The crypto offering also includes the standalone trading platform Revolut X and the euro stablecoin EURR. The company says it served 80 million customers worldwide in August 2026. Yet the incident hits the digital bank in the middle of an expansion. In early September 2026, the US banking regulator OCC granted conditional approval for a national bank charter. Earlier, in August, the launch of the EURR stablecoin had started in Denmark, Poland and Portugal. Affected customers received notification emails in September 2026. However, the company left open how many accounts the breach touched and which authority the attackers impersonated.

    Subscribe to our newsletter

    The best articles of the week, directly delivered into your mailbox.

    How a fake government request deceived Revolut

    Security researchers have documented fraudulent requests for user data under emergency provisions since 2021. The industry term for the pattern is Fraudulent Emergency Data Request. Criminals first take over or spoof the email account of a genuine police or government domain. Through that account, they then request user data as a supposed emergency. The emergency exception bypasses the regular review path via a court order. Companies therefore typically respond within 30 to 60 minutes. That very haste makes the vector attractive. Apple, Meta, Discord and Verizon have already fallen for the scheme, originally through the group Lapsus$ and the Recursion Team. Subsequently, in 2024, the FBI officially warned about the pattern.

    In the Revolut case, the attacker used an account on a legitimate government domain. A spokesperson described a sophisticated external impersonation scam to TechCrunch. The digital bank then blocked the fraudulent address. The incident touched neither systems nor customer funds, according to the company. So far, the provider has not published its own statement on the case.

    "Revolut recently identified a sophisticated external impersonation scam in which an unauthorized third party used a legitimate government domain email to make fraudulent requests for information." - Revolut spokesperson to TechCrunch

    Revolut says it informed the affected authority itself, as well as law enforcement, data protection regulators and financial supervisors. But which body the attackers impersonated remains open. It is equally unclear whether the attacker compromised the email account or spoofed the domain technically. Earlier cases show both variants. For financial institutions, the vector weighs heavily, especially as they must routinely answer official information requests. Moreover, a verification query through a second channel costs time that a request declared urgent does not allow.

    What data the attack exposed

    The customer notification lists a broad set of potentially exposed data. It covers name, date of birth, postal and email address as well as phone number. In addition, the list includes copies of identity documents such as passport and driver's license. Verification selfies from the KYC check, account statements and complete transaction histories also appear. The list thus spans the entire onboarding process of a regulated bank. Still, Revolut speaks of a limited number of directly notified customers. Customer funds themselves remained untouched, according to the provider.

    Mark Karpelès, previously CEO of the crypto exchange Mt. Gox, published a copy of the notification and said the breach hit him too. That version additionally names IBANs, withdrawal logs and complete transaction histories including Bitcoin transactions. As a result, the link between bank account and Bitcoin movements of individual customers potentially sits in outside hands. The on-chain investigator ZachXBT considers the scope limited, but suspects a targeted selection of wealthy users. Whether the incident covers more than a single market also remained open.

    Under Articles 33 and 34 of the GDPR, an incident of this magnitude counts as a high-risk case. Identity documents, biometric selfies and the complete financial history therefore trigger a duty to notify those affected. The Lithuanian data protection authority VDAI has jurisdiction. That is because the provider holds its European banking license through the entity Revolut Bank UAB. That unit also falls under the Bank of Lithuania and the ECB. The spokesperson's statements do not show when Revolut first informed the supervisors.

    Ray Dalio advises 10 to 15% gold and a small Bitcoin position, because he expects a US debt crisis within about three years. Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    The Ethereum Foundation's Protocol Cluster rated 62 EIPs and set December 2029 as the target for a quantum-safe Ethereum base layer. Background

    Ethereum targets a quantum-safe blockchain by 2029

    Financial Products

    Memecoins on Robinhood Chain distort tokenized stock prices

    What separates Dogecoin from Bitcoin is its unlimited supply, and the 2013 satire coin now trades through its own US spot ETF. Basics

    What is Dogecoin? From satire project to ETF asset

    Ray Dalio advises 10 to 15% gold and a small Bitcoin position, because he expects a US debt crisis within about three years. Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    The Ethereum Foundation's Protocol Cluster rated 62 EIPs and set December 2029 as the target for a quantum-safe Ethereum base layer. Background

    Ethereum targets a quantum-safe blockchain by 2029

    Combined KYC and Bitcoin data as a security risk

    A data set of an ID copy, home address and visible Bitcoin holdings is more than a privacy problem. It works as a target list. In the industry, such combinations count as enablers for so-called wrench attacks. These attacks use physical extortion in order to force the handover of crypto access. Anyone who knows how much Bitcoin a person holds and where they live consequently needs no technical attack. Copies of identity documents and selfies further ease the takeover of other accounts. A bank can replace a stolen card number. It cannot replace an exposed identity.

    Case numbers are rising sharply. A CertiK report counted 52 verified wrench attacks in the first half of 2026, with damage around USD 124.1 million. A year earlier, the figures stood at 39 incidents, which corresponds to an increase of 33%. Back then, the damage came to a good USD 10 million. The jump in the damage total is thus far larger than the jump in case numbers. In addition, ID copies and addresses remain usable for years.

    Revolut joins a series of crypto data breaches

    The incident does not stand alone. In August 2026, a leak at wallet provider SafePal hit around 39,798 customers. Private keys and balances nevertheless remained untouched. At Trezor, data on around 67,000 US customers meanwhile leaked out through the shipping service provider ShipMonk. A separate leak at the hardware wallet maker's email service provider also enabled phishing through the legitimate Trezor domain. Overall, the attack surface sat with the manufacturer's service providers in both cases.

    Coinbase delivered the biggest precedent in May 2025. Bribed support staff abroad handed over data on around 70,000 customers. Specifically, the data covered names, addresses, ID images, transaction histories and account balances. The extortionists demanded USD 20 million. Coinbase still did not pay. Estimated remediation costs eventually ranged between USD 180 million and USD 400 million. Altogether, the follow-up costs exceeded the demand many times over. Later, in early 2026, a smaller insider incident with around 30 affected customers followed at Coinbase.

    Ultimately, the attackers in all these cases target not custody but access to the customer database. Crypto-related providers also collect especially complete identity data for regulatory reasons. Self-custody therefore protects only partly, because the ID data already arises at registration. For Revolut, the timing is awkward. The conditional OCC approval and the EURR launch raise regulatory attention. At the same time, the review of the incident is only beginning.

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp

    About the author

    Editorial Office CVJ.CH
    • Website
    • Twitter
    • LinkedIn

    Since 2018, the editorial team at Crypto Valley Journal has been reporting from Zug - the heart of Switzerland’s Crypto Valley - on Bitcoin, cryptocurrency, blockchain, and regulatory developments in digital assets. Behind the publication’s collective editorial voice is a team of writers with backgrounds in financial markets, law, and technology.

    Related Articles

    CVJ weekly review

    Weekly review: SIX and TWINT join sandbox for Swiss franc stablecoin

    Bitcoin Suisse job cuts put up to 60 positions in Zug at risk, as the group moves back-office tasks to Bratislava and Vietnam.

    Bitcoin Suisse plans job cuts at its Zug headquarters

    Of 15,206 wallets that bought the Hunter Biden memecoin LAPTOP, 12,151 lost money, while 88 addresses took home USD 5.57 million.

    Hunter Biden’s memecoin LAPTOP collapses by 99%

    The Revolut data breach exposed ID copies, verification selfies and complete Bitcoin transaction histories to an unknown third party.
    14. September 2026

    Revolut confirms data breach after fake government request

    CVJ weekly review
    12. September 2026

    Weekly review: SIX and TWINT join sandbox for Swiss franc stablecoin

    The revised Clarity Act runs to 630 pages ahead of the first Senate vote on September 15, but Democrats have not yet backed it.
    11. September 2026

    Clarity Act: Senate revises bill ahead of September vote

    twitter image button instagram image button linkedin image button youtube image button

    About Crypto Valley Journal
    About Crypto Valley Journal

    On the pulse of the movement

    • Academy
    • Contact
    • Advertising
    • About us
    • Partner
    • Imprint
    • Privacy
    • Disclaimer
    Search

    Type above and press Enter to search. Press Esc to cancel.