Four days after a phishing email reached 347,000 Trezor newsletter subscribers from Trezor’s own sending domain, having passed every sender-authentication check email has, a second September incident has run the same play against a different kind of target — and this time the payload was not a link. It was the files. The British fintech Revolut has told a subset of its customers that their personal and financial records — including full Bitcoin transaction histories — were disclosed to an unauthorised third party after the firm treated a fraudulent information request as a genuine government demand.
The mechanism is the part worth understanding, because it is not a spoof in the ordinary sense. According to the customer notice, the request came from a mailbox created inside a real government agency’s own domain infrastructure, carrying genuine domain authentication credentials. It therefore passed Sender Policy Framework, DomainKeys Identified Mail and Domain-based Message Authentication, Reporting and Conformance — SPF, DKIM and DMARC, the three protocols whose entire job is to establish that a message really came from the domain it claims. It did come from that domain: on the notice’s account the mailbox itself was unauthorised, created inside infrastructure that was otherwise genuine. Revolut fulfilled the request, in its own words, “under the reasonable belief that it was an authentic government agency request”.
What the notice says was disclosed
The customer email began circulating on 11 September 2026. Former Mt. Gox chief executive Mark Karpelès, who identified himself as a recipient, received it with the subject line “Urgent security update about your Revolut account” at 21:59 UTC on Friday 11 September, and posted substantial excerpts at 07:06 UTC on Saturday 12 September. The Crypto Times reported the notice in detail on 12 September, and that report is the source for the notice text quoted here. Grouped as the notice groups them, the categories are:
- Identity: full name, date of birth, occupation.
- Contact: postal address, email address, telephone number.
- Documents and verification: a copy of the identity document — passport or driving licence — and the facial verification image submitted at onboarding. The notice states that “no biometric facial telemetry data was involved or compromised”, drawing a distinction between the selfie itself and the derived template used to authenticate a face.
- Financial: account statements including the IBAN, account status, opening date and wallet reference number; withdrawal records; and full transaction history, including Bitcoin.
Equally important is what the notice does not describe as taken: wallet private keys, login passwords, card PINs and account balances. No customer funds have been reported moved. Revolut says it later contacted the agency to verify the request — and in doing so alerted that authority to the presence of an unauthorised account on its own domain — then blocked the address across internal systems, notified regulators and applied “precautionary protection measures” for affected customers. A spokesperson described it as a “sophisticated external impersonation scam” affecting a “limited” number of customers.
Revolut customers were targeted in a fraudulent emergency data request sent via an email at a "government agency."
— @MagicalTux September 12, 2026
Why a transaction history is worse than an email leak
It is tempting to file this alongside the routine password dumps, and the pairing is what makes that wrong. Revolut records Bitcoin activity for customers who buy, sell or withdraw through its app and its separate venue Revolut X. What left the firm, on the notice’s own description, pairs a complete transaction history and a wallet reference number with a passport image, an onboarding selfie, a residential address and an IBAN.
That combination does three things a credential leak does not. It lets chain analysis begin from a legal name rather than from an unnamed cluster of addresses, which inverts the usual difficulty of the exercise. It supplies precisely the fields used in account-recovery and customer-verification workflows, which is the raw material for social engineering against the victim’s other accounts. And — the reason on-chain investigator ZachXBT flagged it — it pairs a home address with an estimate of how much bitcoin the person at that address has touched — a risk sharpened by on-chain investigator ZachXBT’s reading of the incident. Posting to his Telegram channel Investigations, he described it as likely limited in size and said it “seems to have been targeted at high net worth users”. The inference from that to physical-coercion risk is the desk’s, and it is the risk covered in the last section of Field Guide #43. He also posted screenshots at 06:51 UTC on 12 September indicating he had been blocked by both of Revolut’s X accounts.
Idk why I am blocked by both Revolut accounts.
— @zachxbt September 12, 2026
Revolut’s public response, as of 09:13 UTC on 12 September, was a reply from the @revolutsupport account at 06:42 UTC saying “We take data protection and privacy concerns very seriously”, without facts beyond the customer email. No numbered press statement and no post from the main account had appeared. The two posts embedded in this article are reproduced as rendered in The Crypto Times’ report of 12 September, which is where the desk read them; the status URLs are given so readers can check them at source.
The pattern: authentication passed, and it was the wrong question
This is the second time in five days that the desk has had to write the same sentence, and the repetition is the story. On 9 September, a phishing email claiming a “Critical Security Alert: STM32 Entropy Vulnerability” reached approximately 347,000 Trezor newsletter subscribers from help@trezor.io, passing SPF, DKIM and DMARC, because the attacker was inside Trezor’s compromised Brevo account — covered in Friday’s update. On 11 September, a fraudulent legal request reached Revolut from inside a government domain, passing the same three checks, because the attacker was inside that domain.
The structural point is that SPF, DKIM and DMARC answer “did this message come from this domain?” and nothing else. They do not answer “is the person at that mailbox authorised to ask this?” Both incidents defeated the checks by satisfying them honestly. The two differ in one way that matters for how much damage is possible: the Trezor case touched only opt-in newsletter addresses and required the recipient to act, whereas the Revolut case ran through a legal-request process that trusted domain authentication without out-of-band verification and required nothing of the customer at all. A person who did everything right was exposed anyway.
Field Guide #43’s rule was “check the sending domain”. Friday’s update recorded that a compromised email service provider defeats it. This incident extends the revision one step further, and the desk states the rule in its final form: provenance is not authorisation. For an individual, that means any message asking for a seed phrase, backup or extended public key is phishing regardless of how impeccably it authenticates. For an institution, it means a request for customer records is verified by calling the agency back on a channel the requester did not supply — not by checking the headers on the request.
What is confirmed, and the five things that are not
Confirmed by matching the notice text as posted by a named recipient against The Crypto Times’ account of it: Revolut accepted an information request appearing to originate from a government agency; the sending mailbox operated on that agency’s domain and passed domain authentication; Revolut subsequently treated the mailbox as unauthorised and blocked it internally; and the firm notified regulators and emailed affected customers. The disclosed categories include KYC images and Bitcoin transaction histories, with selfie images included and derived biometric telemetry excluded.
Unconfirmed, and the desk is not going to estimate any of it: how many customers were in the response; which country or agency was impersonated; on what date the files left the firm; whether other institutions received requests from the same mailbox; and whether the third party has reused the information. Naming the agency would let other banks and exchanges search their own legal-request logs for messages from the same mailbox; that is the desk’s view of where the highest-value disclosure still sits, and it is the one that would let the rest of the industry find out whether it was hit too.
Four earlier Revolut matters circulated alongside this story over the weekend and none of them is evidence for it: a September 2022 case in which Lithuania’s State Data Protection Inspectorate recorded 50,150 customers affected by a social engineering attack on staff; a July 2026 cybercrime forum listing claiming 75 million records for sale, which Revolut disputed after an internal review as likely fabricated; a February 2026 matter in which the firm reported a former employee to law enforcement over an alleged ransom threat involving KYC data; and a May 2026 operational fault in which a third-party price feed briefly displayed Bitcoin near zero. Different methods, different years. The desk lists them only so readers who encounter them do not fold them into this week’s count.
What to do if you were notified
Revolut’s public fraud guidance, as summarised in the reporting, directs customers to in-app chat rather than to links in unsolicited email or unexpected calls, and that guidance is load-bearing here: the exposed set contains the exact identity documents and account details used in verification and account-recovery flows, so a caller who can recite your date of birth, occupation, address and IBAN has proved nothing. Treat any contact citing the leak as hostile until verified through a channel you initiated.
The self-custody point is narrower than the obvious one, and the desk wants to be careful not to over-claim it. No private keys were disclosed, so this is not an argument that custodial bitcoin was less safe from theft. What was disclosed is the linkage — the map from a legal identity to on-chain activity — and that is a category of harm that self-custody does not prevent either, because the linkage was created at onboarding by a regulated exchange, not by the wallet. The honest lesson is about data minimisation and retention: a transaction history from 2021 cannot leak if it is no longer held, which is the same conclusion Field Guide #43 reached about a shipping contractor holding hardware-wallet buyers’ home addresses it had certified in writing were deleted.
Marker AH1, set today: Revolut names the impersonated government agency or publishes an affected-customer count by Wednesday 30 September. Neither had happened as of 06:10 UTC on Sunday 13 September. The desk will also watch whether any regulator posts a filing, and whether a second institution reports a request from the same mailbox — the latter being the finding that would turn this from one firm’s failure into a sector-wide one.
Method: prices, funding, open interest, basis, mining and on-chain figures in this article are pulled directly by Bitcoin Mastery at the timestamp stated — Bitstamp BTC/USD daily candles for closes, Binance BTCUSDT spot and USDT-margined perpetual for intraday, open interest, funding and account ratios, Binance COIN-M quarterly contracts for basis, mempool.space for difficulty, hashrate, pool shares, fees, address balances and individual Bitcoin transactions, blockstream.info’s Liquid API for sidechain block heights, hashes, timestamps and transaction counts, alternative.me for the Fear & Greed series, CoinGecko for altcoin daily prices, Farside Investors’ table for ETF flows and US Treasury CMT par yields for rates. Transaction counts, fee totals, byte totals and OP_RETURN payloads are recomputed from the full confirmed transaction list of the address concerned, not read off a summary. Where a third-party figure is cited we name the source and its date; where two sources disagree we print both. Every streak or extreme figure is published with the first date of its series in the same sentence.
Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset, token or exchange-traded fund, including MSTR, L-BTC, HYPE, ORDI or the LEAF token where discussed above. Token sales of the kind described in this article are unaudited, frequently anonymous and have no obligation to deliver anything in return for a payment; treat any coin sent to one as capable of going to zero. Do your own research and consult a licensed financial advisor before making investment decisions.