Revolut confirmed on 12 September 2026, after a customer notice was posted by the researcher ZachXBT, that an unauthorised third party had used a legitimate government agency’s email domain to submit fraudulent requests for customer information, and that the company had answered them. The data released for what Revolut called a very limited group of customers included names, birth dates, addresses, occupations, copies of passports and driving licences, onboarding selfies, IBANs, account statements and full transaction histories including cryptocurrency activity. Funds and systems were not touched, the company said.
Revolut said it had alerted the agency that its identity was being abused, along with law enforcement, data protection and financial regulators. It named none of them. The Register reported that individuals claiming responsibility demanded 10,000 bitcoin, about $782 million, and threatened daily leaks. Revolut did not acknowledge the demand.
The Request Channel As The Attack Surface
Every regulated financial firm runs a desk that answers lawful requests from police and regulators. The desk is built to comply quickly, and its check on a request is largely that it comes from the right domain. An attacker who can send from a government domain, whether through a compromised mailbox or a forwarding rule, inherits that trust. The corpus filed the same shape at 26-0713, where the support ticket was the breach; here the ticket came with a badge.
What Was Released Is The Onboarding File
The fields describe a complete know-your-customer record: the identity document, the selfie taken to match it, the bank details and the movement of money. The reissuance line the corpus draws at 26-0324 applies to most of it. A passport can be replaced; a selfie cannot, and neither can a year of transactions. For customers with cryptocurrency activity in the record, the file is also a list of people known to hold bearer assets, the position recorded at 25-0530.
Limited, Unnamed, And Then Again
The count is not published. The agency is not named. The demand is an attacker’s claim. And on 25 September The Register reported a second, separate Revolut customer-data incident in the same month, tied to the brokerage partner DriveWealth. The file is graded medium on the gaps, not on the fact, which the company confirmed in its own words.
Compiled from Revolut’s customer notice and statements as reported, listed below. The agency, the jurisdiction and the count were not disclosed. The bitcoin demand is an attacker claim reported by one outlet and is carried as such. Graded medium. Corrections: corrections@forensicpost.com.