Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Crypto Security & Data Breach News
Revolut handed sensitive customer data to a fraudster after being deceived by a fake government request. The attacker sent data requests using an unauthorized email account on a legitimate government agency’s official domain. Those requests passed Revolut’s authentication checks. The company later determined they were not genuine.
The exposed data included passport and driver’s license copies, identity verification selfies, full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers. Financial data handed over included account statements, IBAN numbers, wallet reference numbers, withdrawal records, and complete transaction histories, including <a href="https://xpertsstudio.com/sgx-moves-to-open-bitcoin-ether-perpetual-futures-to-u-s-institutions/” title=”SGX Moves to Open Bitcoin, Ether Perpetual Futures to U.S. Institutions”>Bitcoin (BTC). Revolut confirmed no biometric facial data was involved.
A company spokesperson confirmedthe breach to TechCrunch on Sept. 13. They described it as “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” Revolut said it blocked the address after identifying the fraud. It also alertedthe relevant government agency, law enforcement, data protection authorities, and financial regulators.
High-Net-Worth Users Appear To Have Been Targeted
Revolut said it contacted affected customers directly. Some customers reported receiving notification emails on Sept. 12. The company said its systems and customer funds were unaffected. It declined to disclose how many customers were hit, which country they were in, or which government agency was impersonated.
Former Mt. Gox CEO Mark Karpelès said he was among those affected. He shared Revolut’s customer notification publicly. On-chain investigator ZachXBT also alerted followers to the breach on X. He wrote that the incident appeared to target high-net-worth users, a concern given the recent rise in physical attacks on known crypto holders.
The breach drew swift criticism on social media around Know Your Customer (KYC) rules. Marc Zeller wrote that he had woken up to find all his data leaked. He added that the episode was “a sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way.” Several other users echoed similar concerns about mandatory identity data collection creating risk without protection.
Related Article:ECB Touts Digital Euro Privacy as Revolut Launches Euro Stablecoin EURR, Forbes
Breach Lands as Revolut Pursues US Bank Charter
The timing is significant for Revolut. Earlier in September 2026, the company received conditional approval from the US Office of the Comptroller of the Currency toward its goal of establishing a national bank in the US. The proposed bank is expected to offer traditional banking products alongsidestablecoin services.
Revolut also began rolling out EURR, its euro-backed stablecoin, to customers in Denmark, Poland, and Portugal in August 2026. The company serves 80 million customers globally. It is also weighing an IPO. The breach adds to a pattern of data security incidents hitting crypto and fintech firms in recent months.
Hardware wallet maker Trezor disclosed last week that a breach at shipping provider ShipMonk affected roughly 67,000 US customers. That substantially expanded a case Trezor first reported in August 2026. Trezor also separately disclosed that attackers used a third-party email provider breach to send phishing emails from its legitimate domain, an approach similar to how Revolut’s attacker exploited a trusted domain. Crypto wallet provider SafePal disclosed that a flaw in an order-tracking system had exposed data belonging to approximately 39,798 customers.
This article contains links to third-party websites or other content for information purposes only (“Third-Party Sites”). The Third-Party Sites are not under the control of CoinMarketCap, and CoinMarketCap is not responsible for the content of any Third-Party Site, including without limitation any link contained in a Third-Party Site, or any changes or updates to a Third-Party Site. CoinMarketCap is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement, approval or recommendation by CoinMarketCap of the site or any association with its operators. This article is intended to be used and must be used for informational purposes only. It is important to do your own research and analysis before making any material decisions related to any of the products or services described. This article is not intended as, and shall not be construed as, financial advice. The views and opinions expressed in this article are the author’s [company’s] own and do not necessarily reflect those of CoinMarketCap.
Source: coinmarketcap.com
