Revolut says limited user KYC data and Bitcoin trading records may have been exposed

Revolut says limited user KYC data and Bitcoin trading records may have been exposed

N
News Editor
2026-09-13 02:16:27
Revolut said an unauthorized third party used an email address hosted under a real government-domain name to submit fraudulent customer data access requests, leading to the exposure of sensitive information belonging to a small number of clients. The company described the incident as a "complex external impersonation scam" and said the relevant email account has now been blocked. Revolut added that its internal systems and customer funds were not affected. The information that may have been disclosed includes names, dates of birth, home addresses, email addresses, phone numbers, copies of identity documents such as passports and driver’s licenses, verification selfies, account statements, IBAN details, withdrawal records, and full transaction histories, including Bitcoin transactions. Former Mt. Gox CEO Mark Karpelès said he was among those affected. Revolut did not disclose how many customers were impacted, whether the incident was limited to a single market, or which government entity owned the spoofed domain. The company said it has notified the relevant government body, law enforcement, data protection authorities, and financial regulators. On-chain investigator ZachXBT said the scale may be limited, though high-net-worth users may have been targeted.

Revolut said on Sept. 13 that an unauthorized third party used an email address hosted under a legitimate government-domain name to submit fraudulent requests for customer information, exposing sensitive data belonging to a small number of users.

The company described the case as a "complex external impersonation scam" and said the email account involved has been blocked. Revolut also said its systems and customer funds were not affected.

The data that may have been exposed includes names, dates of birth, residential addresses, email addresses, phone numbers, copies of identity documents such as passports and driver’s licenses, identity verification selfies, account statements, IBAN details, withdrawal records, and complete transaction histories, including Bitcoin trading records.

Former Mt. Gox CEO Mark Karpelès said he was one of the affected users.

Revolut did not disclose the number of impacted customers. It also did not say whether the incident was confined to a single market, nor did it identify the government institution whose domain name was abused. The company said it has notified the relevant government agency, law enforcement, data protection authorities, and financial regulators.

On-chain investigator ZachXBT said the scale of the incident may be limited, but the targets may have included high-net-worth users.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.