๐Ÿ“… Saturday, 12 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Revolut Bocorkan Riwayat Bitcoin Nasabah ke Penipu Bermodal Email Resmi Pemerintah

Revolut Leaks Customer Bitcoin Records to Scammers Using Official Government Email

Revolut handed over customer Bitcoin transaction histories and personal identification data to an unauthorized party who sent a request using an email address from an official government domain. The incident came to light on Friday, September 11, 2026, after on-chain investigator ZachXBT posted a copy of the customer notification on his Telegram channel.

The data request email passed domain authentication checks without issue. The reason was straightforward: the email was sent directly from a legitimate government agency domain, rather than a spoofed or lookalike address.

The incident demonstrates a breach that required no server hacking at all, relying instead on manipulating the company’s legal compliance procedures.

Extensive List of Surrendered Data

Several customers began receiving notification emails regarding the status of their data on the same day as ZachXBT’s findings. The notice detailed the information that had been compromised, ranging from basic personal details such as full name, date of birth, occupation, postal address, email, to personal phone numbers.

The shared documents went far beyond contact details. Revolut also handed over copies of identity documents, including customer passports or driver’s licenses, selfie photos used for KYC verification, account status information, opening dates, and IBAN numbers.

On the crypto side, the fraudsters obtained victims’ Bitcoin wallet reference numbers. Withdrawal records and complete transaction histories detailing Bitcoin movements were also provided by the company.

Revolut outlined the scope of the privacy breach to curb further speculation. The company emphasized that certain sensitive data was not compromised: facial biometrics, private keys, account passwords, and full payment card details.

Targeting High-Net-Worth Users

The company has not disclosed the exact number of victims whose profiles were leaked. Revolut’s operational milestone of serving over 80 million global customers as of August 2026 reflects the platform’s overall scale, not the scope of affected users.

Based on his initial observations, ZachXBT estimated that the data disclosure occurred on a limited scale. The attackers appeared to cherry-pick targets, specifically focusing on high-net-worth users.

Revolut explained that staff processed the data because they had a “reasonable belief that it was an authentic request from a government agency.” They maintained that the incident was strictly an unauthorized information disclosure, with no internal system compromise.

The name of the government agency whose email domain was used in the scam was not mentioned in the notification letter. The identity of the perpetrator behind the fraudulent request also remains unknown.

The incident serves as a stark reminder of a fundamental truth in financial security: even the strictest cryptographic protections fall apart when front-desk administrative staff are fooled by a government agency letterhead.

Reported by crypto.news.

Read also: Law Firm Breaches Double - Data on 69,461 Coinbase Users Exposed


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share