REGULATORYTwenty-point deficit erased: Arch Manning leads Texas Longhorns past No. 1 Ohio StateSep 13, 2026
JNJApollo in talks to buy J&J's DePuy Synthes at close to $20 billionSep 13, 2026
SHOP$160 Bernstein target on Shopify lands below Street consensus as stock trades at 51x forward earningsSep 13, 2026
$BTCRevolut data breach exposes KYC and Bitcoin transaction records after fake government domain requestSep 13, 2026
ABNBOver $40 million per program, 1,234 miles: Ohio State arrives in Austin for a Texas rematch with playoff stakesSep 13, 2026
EARNINGSLululemon (LULU) cuts full-year guidance again as leggings shrink about 20% and China sentiment turnsSep 13, 2026
DEALSPlusAI targets $800 million valuation in Texas Ventures SPAC dealSep 13, 2026
IMUXImmunic board contracts to nine seats after Nash departureSep 13, 2026
REGULATORYTwenty-point deficit erased: Arch Manning leads Texas Longhorns past No. 1 Ohio StateSep 13, 2026
JNJApollo in talks to buy J&J's DePuy Synthes at close to $20 billionSep 13, 2026
SHOP$160 Bernstein target on Shopify lands below Street consensus as stock trades at 51x forward earningsSep 13, 2026
$BTCRevolut data breach exposes KYC and Bitcoin transaction records after fake government domain requestSep 13, 2026
ABNBOver $40 million per program, 1,234 miles: Ohio State arrives in Austin for a Texas rematch with playoff stakesSep 13, 2026
EARNINGSLululemon (LULU) cuts full-year guidance again as leggings shrink about 20% and China sentiment turnsSep 13, 2026
DEALSPlusAI targets $800 million valuation in Texas Ventures SPAC dealSep 13, 2026
IMUXImmunic board contracts to nine seats after Nash departureSep 13, 2026

Revolut data breach exposes KYC and Bitcoin transaction records after fake government domain request

Customer identity verification data and Bitcoin ($BTC) transaction records held at Revolut were accessed through a fraudulent request that impersonated a government domain, the company confirmed. Onchain investigator ZachXBT speculated the…

By Kwame Asante·Sep 13, 2026·1 min read·crypto·$BTC

Key takeaways

  • Revolut confirmed that customer KYC identity verification data and Bitcoin transaction records were accessed through a fraudulent request that impersonated a government domain.
  • The breach exposed two data categories: KYC identification documents submitted during onboarding and Bitcoin transaction records showing patterns, counterparties, and timing of on-chain activity.
  • The attack exploited compliance frameworks that treat requests from regulatory or law enforcement addresses as authoritative, allowing a spoofed government source to bypass normal scrutiny.
  • Onchain investigator ZachXBT speculated the fraudulent request may have been engineered to deliberately target high-net-worth accounts rather than harvest data broadly.
  • Revolut has not disclosed how many users were affected or when the fraudulent request was submitted.

Customer identity verification data and Bitcoin ($BTC) transaction records held at Revolut were accessed through a fraudulent request that impersonated a government domain, the company confirmed. Onchain investigator ZachXBT speculated the incident targeted high-net-worth users.

The breach covered two distinct categories of data. KYC files contain the identification documents customers submit during onboarding. Bitcoin transaction records add the behavioral layer: the pattern, counterparties, and timing of on-chain activity. Together, they link a verified identity to its financial footprint on the network without requiring any direct access to the blockchain.

The attack vector relied on a fake government domain. Compliance frameworks at financial institutions generally treat requests from regulatory or law enforcement addresses as authoritative, which means a convincingly spoofed government source can move sensitive data outside the scrutiny applied to ordinary inquiries.

ZachXBT, who tracks illicit fund flows on public blockchains, characterized the exposure as potentially deliberate. His read: the fraudulent request may have been engineered to surface records for high-net-worth accounts specifically, rather than to harvest data broadly.

That framing shifts the incident from opportunistic breach toward targeted reconnaissance. KYC paired with $BTC transaction history hands an attacker a profile that the public blockchain alone cannot supply.

Revolut has not disclosed how many users were affected or when the fraudulent request was submitted.

Related reading

Share
Source: theblock.co
© 2026 NewsMeter

Frequently asked

How did attackers gain access to the Revolut data?

They used a fraudulent request that impersonated a government domain, exploiting compliance frameworks that treat regulatory or law enforcement requests as authoritative.

What types of data were exposed in the breach?

KYC files containing customer identification documents from onboarding and Bitcoin transaction records showing the pattern, counterparties, and timing of on-chain activity.

Who does ZachXBT believe was targeted?

ZachXBT speculated the incident deliberately targeted high-net-worth users, suggesting the request was engineered to surface records for those specific accounts.

Why is combining KYC data with Bitcoin transaction records significant?

Together they link a verified identity to its financial footprint on the network, giving an attacker a profile that the public blockchain alone cannot supply.

How many users were affected by the breach?

Revolut has not disclosed how many users were affected or when the fraudulent request was submitted.