Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Revolut Handed Over Customer Bitcoin Records After a Forged Government Request Passed Its Security Checks

Revolut told a number of customers this past week that their personal and financial data, including Bitcoin transaction histories, was handed over to someone impersonating a government agency, according to a customer notice shared by on-chain investigator ZachXBT.
The request looked real. According to the notice, it was sent from an unauthorized email account that used the government agency's actual domain and carried valid domain authentication credentials, the kind of technical signals (SPF, DKIM, DMARC) email systems rely on to confirm a message came from where it says it did. Revolut's own language, as reported by Crypto.news, says the company fulfilled the request "under the reasonable belief that it was an authentic government agency request."
This wasn't some sloppy phishing email with a misspelled domain. Whoever sent it either compromised a real account inside that agency's email system or found a way to create one, and it was convincing enough to get past whatever review process Revolut has for law enforcement requests.
What got exposed
According to the notice, the disclosed data included customers' full names, dates of birth, occupations, postal addresses, email addresses and phone numbers. It also included copies of passports or driver's licenses and the verification selfies customers submitted when they opened their accounts.
On the financial side, the notice says Revolut turned over account statements, IBANs, account status and opening dates, Bitcoin wallet reference numbers, withdrawal records, and complete transaction histories including Bitcoin activity. Revolut said biometric facial telemetry data was not part of what went out.
ZachXBT, who publicized the notice, said the incident "is likely limited in size" but "seems to have been targeted at high net worth users." That's his read, not a confirmed figure from Revolut. Multiple customers reportedly received alert emails on Friday, September 11, but neither ZachXBT nor the portion of Revolut's notice that circulated gives an actual count of how many accounts were affected.
What's still unknown
Revolut's notice doesn't name the government agency involved. It doesn't say how the unauthorized sender got access to that agency's domain. It doesn't give a date for when the original fraudulent request went out. And it doesn't say whether the agency in question has launched its own investigation into how its email infrastructure was used this way.
Coverage from Crypto Briefing and TradingView both note that Revolut had not issued a broader public comment on the exposure beyond the customer notice itself as of publication. No regulator has announced an investigation into Revolut over this incident. No charges have been filed against anyone.
The notice does not claim an intruder broke into Revolut's own systems, accessed customer accounts directly, or moved any funds. This was a data disclosure triggered by a fraudulent request, not a hack of Revolut's infrastructure or a theft from customer wallets.
The compliance bind
There's a legitimate case to be made for why banks and fintechs respond quickly to government data requests. Anti-money-laundering rules and law enforcement subpoenas exist for real reasons, and a financial institution that stonewalls every request risks its own regulatory exposure. Revolut, like any bank, has an obligation to cooperate with legitimate government inquiries, and domain authentication is a standard, widely-trusted method for verifying that an email actually came from where it claims to.
If a message that passes SPF, DKIM and DMARC checks can still be a forgery, the entire framework banks use to decide when to hand over your passport scan and your Bitcoin history needs a second layer of verification that doesn't rely purely on the domain looking legitimate.
Revolut has built its brand on being the crypto-friendly alternative to legacy banks, courting users who specifically wanted an institution comfortable with digital assets. An incident where Bitcoin wallet references and full transaction histories walked out the door because of a forged email is a direct hit to that pitch.
The unresolved question is whether any government agency, in the UK where Revolut is based or elsewhere, will confirm which of its domains was compromised and open a formal inquiry. Until that happens, affected customers are left knowing their financial history and ID documents are out there, without knowing exactly who has them or how many other accounts were touched.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.