MACRO10-year Treasury yield reaches 5.07 percent, highest since 2007Oct 1, 2026
FPHFive Point Holdings Extends Great Park Development Agreement to 2028Oct 1, 2026
$BTCBitcoin Dips 3.2% as Clarity Act Vote Fails in SenateOct 1, 2026
EARNINGSOshkosh Backlog Slides 3.3% Year Over Year Amid Margin PressureOct 1, 2026
WORLDMaine poll shows Collins leads Jackson by 3 pointsOct 1, 2026
WORLDFDA nominee Heidi Overton declines to call healthcare a human rightOct 1, 2026
WORLDFox News outdraws CNN and MS NOW combined in Q3 2026Sep 30, 2026
RVPRetractable Technologies declares quarterly preferred dividendsSep 30, 2026
MACRO10-year Treasury yield reaches 5.07 percent, highest since 2007Oct 1, 2026
FPHFive Point Holdings Extends Great Park Development Agreement to 2028Oct 1, 2026
$BTCBitcoin Dips 3.2% as Clarity Act Vote Fails in SenateOct 1, 2026
EARNINGSOshkosh Backlog Slides 3.3% Year Over Year Amid Margin PressureOct 1, 2026
WORLDMaine poll shows Collins leads Jackson by 3 pointsOct 1, 2026
WORLDFDA nominee Heidi Overton declines to call healthcare a human rightOct 1, 2026
WORLDFox News outdraws CNN and MS NOW combined in Q3 2026Sep 30, 2026
RVPRetractable Technologies declares quarterly preferred dividendsSep 30, 2026

Revolut data breach exposes KYC and Bitcoin transaction records after fake government domain request

Customer identity verification data and Bitcoin ($BTC) transaction records held at Revolut were accessed through a fraudulent request that impersonated a government domain, the company confirmed. Onchain investigator ZachXBT speculated the…

By Kwame Asante·Sep 13, 2026·1 min read·crypto·$BTC

Key takeaways

  • Revolut confirmed that customer KYC identity verification data and Bitcoin transaction records were accessed through a fraudulent request that impersonated a government domain.
  • The breach exposed two data categories: KYC identification documents submitted during onboarding and Bitcoin transaction records showing patterns, counterparties, and timing of on-chain activity.
  • The attack exploited compliance frameworks that treat requests from regulatory or law enforcement addresses as authoritative, allowing a spoofed government source to bypass normal scrutiny.
  • Onchain investigator ZachXBT speculated the fraudulent request may have been engineered to deliberately target high-net-worth accounts rather than harvest data broadly.
  • Revolut has not disclosed how many users were affected or when the fraudulent request was submitted.

Customer identity verification data and Bitcoin ($BTC) transaction records held at Revolut were accessed through a fraudulent request that impersonated a government domain, the company confirmed. Onchain investigator ZachXBT speculated the incident targeted high-net-worth users.

The breach covered two distinct categories of data. KYC files contain the identification documents customers submit during onboarding. Bitcoin transaction records add the behavioral layer: the pattern, counterparties, and timing of on-chain activity. Together, they link a verified identity to its financial footprint on the network without requiring any direct access to the blockchain.

The attack vector relied on a fake government domain. Compliance frameworks at financial institutions generally treat requests from regulatory or law enforcement addresses as authoritative, which means a convincingly spoofed government source can move sensitive data outside the scrutiny applied to ordinary inquiries.

ZachXBT, who tracks illicit fund flows on public blockchains, characterized the exposure as potentially deliberate. His read: the fraudulent request may have been engineered to surface records for high-net-worth accounts specifically, rather than to harvest data broadly.

That framing shifts the incident from opportunistic breach toward targeted reconnaissance. KYC paired with $BTC transaction history hands an attacker a profile that the public blockchain alone cannot supply.

Revolut has not disclosed how many users were affected or when the fraudulent request was submitted.

Related reading

Share
Source: theblock.co
© 2026 NewsMeter

Frequently asked

How did attackers gain access to the Revolut data?

They used a fraudulent request that impersonated a government domain, exploiting compliance frameworks that treat regulatory or law enforcement requests as authoritative.

What types of data were exposed in the breach?

KYC files containing customer identification documents from onboarding and Bitcoin transaction records showing the pattern, counterparties, and timing of on-chain activity.

Who does ZachXBT believe was targeted?

ZachXBT speculated the incident deliberately targeted high-net-worth users, suggesting the request was engineered to surface records for those specific accounts.

Why is combining KYC data with Bitcoin transaction records significant?

Together they link a verified identity to its financial footprint on the network, giving an attacker a profile that the public blockchain alone cannot supply.

How many users were affected by the breach?

Revolut has not disclosed how many users were affected or when the fraudulent request was submitted.