Researchers Uncover Scheme of Fake Crypto Requests in Revolut
- Analysts have discovered how Revolut transmitted customer data through fake requests.
- The incident centered not on a breach of the banking application itself, but on the abuse of the channel through which financial institutions interact with government bodies.
- 680 Revolut customers may have been affected by the leak.
- According to researchers, the attackers used public crypto transactions and wallet addresses to obtain KYC data of potentially wealthy users.
The fintech company Revolut is facing the consequences of a data leak affecting around 680 customers after attackers used compromised Italian government email accounts to send fake requests to the fintech company. This is reported by FT and International Cyber Digest.
‼️ BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments.
They say the operation targeting Revolut ran for six months, and that they used Italian law... pic.twitter.com/ZYGWZEc0tL
--- International Cyber Digest (@IntCyberDigest) September 14, 2026
In light of the publication of user data and possible ransom demands, researchers are revealing the mechanics of the attack, while lawyers and human rights advocates point to a systemic issue in verifying government requests in the financial sector.
Additionally, some claims are being disseminated by the alleged attackers themselves. Revolut has not confirmed all the disclosed figures and details.
Revolut disclosed customer data through a fraudulent request --- among them, the history of Bitcoin transactions
13.09.2026
Read
According to early Revolut investor and independent analyst Max Karpis, the company has received ransom demands, and individuals claiming to possess the stolen files have begun posting copies of documents and selfies of customers on Telegram.
After Revolut's data breach, the company has reportedly received ransom demands: pay up, or they'll release customer files.
People claiming they hold the pack are posting ID copies and selfies on Telegram and saying they will drip more every day. One figure doing the rounds is...
--- Max Karpis (@maxkarpis) September 14, 2026
At the same time, Karpis emphasized that the claimed amount of 10,000 BTC has not been confirmed by Revolut, and the information should be taken with caution.
*<<Revolut still claims a "limited" scale of the incident, and the app and funds were not hacked. This is extortion after a Revolut employee transmitted KYC to an unauthorized email address on a legitimate government domain. Payment would not return passports>>, he wrote.
Karpis also urged potentially affected users to take additional security measures: if possible, freeze credit lines, set a new access code and transaction alerts in the app, and avoid contact with individuals who already know the user's IBAN or previous cryptocurrency transactions.
Separately, he advised considering the possibility of replacing passports, as in some countries, after document compromise, one can cancel the old number and obtain a new one. Meanwhile, the expert warned of another potential fraud scheme: offers to "delete the file" for money may be attempts at re-extortion.
How attackers could obtain cryptocurrency client data
According to a user of platform X under the account Korra, a hacker using the alias IAmNotAVillain employed a so-called "spray and pray" tactic: sending Revolut hundreds of cryptocurrency transaction IDs and deposit addresses and requesting information about the associated accounts.
‼️ BREAKING: Duel can report that the Revolut hacker used a "spray and pray" strategy, sending hundreds of cryptocurrency transaction IDs to Revolut and asking for the associated account details. Revolut complied.
This explains the sheer volume of data the hackers were able to... pic.twitter.com/RqGsuEIkMZ
--- Korra (@korraflow) September 15, 2026
According to Duel, such requests were sent under the guise of a forged European Investigation Order. Revolut allegedly provided archives containing client data in response.
Researchers stated that they received and verified authentic copies of emails in .eml format. One of them contained 10 folders, each dedicated to a specific client. According to Duel, the folders contained:
- photos of identity documents;
- selfies for verification;
- account information;
- unedited transaction data.
The password for the encrypted ZIP archive, according to researchers, was sent in a separate email.
This scheme also explains why the attackers could specifically target information about wealthy Revolut clients. Public blockchains allow visibility of addresses and transactions, thus a cryptocurrency transaction could be used as a sort of search key for requests to a centralized financial institution.
Researchers claim that the hacker sent Revolut hundreds of transaction hashes and deposit addresses that he believed were linked to high-asset clients. After that, the company allegedly returned information about the relevant users.
Separate claims about 147 GB of data allegedly stolen from Italian government systems, as well as the publication of client data, are being circulated by researchers and individuals claiming to be in contact with the attackers.
Human rights advocate and president of the Open Dialogue Foundation, Lyudmyla Kozlovska, noted that new documents confirm that on July 24, 2026, Revolut refused to directly disclose information in response to a request covering 198 hashes. According to her, 169 of them were related to Revolut Ltd in the UK, while another 29 were linked to a Swiss legal entity.
New evidence shows: (1) @Revolut did apply the one refusal ground the law gives it. (2) the attackers targeted in their malicious request high-value clients using blockchain transactions.
Documents show that on 24 July 2026, on a request covering 198 hashes, Revolut refused... https://t.co/Hs4eHdvBuo
--- Lyudmyla Kozlovska 🇪🇺🇺🇦 (@LyudaKozlovska) September 15, 2026
According to Kozlovska, the company applied the legal ground for refusal—jurisdictional limitation. The request only concerned accounts at Revolut Bank UAB in Lithuania, while for other cases, the applicant was directed to the British mutual legal assistance procedure.
At the same time, she emphasized that European anti-money laundering rules do not impose a separate obligation on banks to verify the authenticity of the party behind an authenticated state request.
<
>, Kozlovska stated.
What Victims Should Do and Why the Incident Has Broader Implications
Kozlovska urged European citizens to contact their Members of the European Parliament and demand urgent hearings on the use of mass collection of financial data as a tool for attacks.
She also pointed out a potentially broader issue: a similar risk may apply to banks, cryptocurrency exchanges, and payment services in jurisdictions where FATF rules and relevant AML legislation are in effect.
According to her, financial institutions are required to respond to properly formatted government requests, while the mechanisms for verifying who is actually behind such requests may be limited.
Kozlovska noted that the issue has already been raised before the European Parliament by human rights organizations, victims, and experts with the support of the Open Dialogue Foundation. She highlighted that this year the European Parliament, in a resolution dated June 18, 2026, specifically marked the risk of transnational financial repression.
At the time of writing, Revolut had not published specific recommendations for customers regarding further actions related to the incident on its page on X.
It is worth noting that recently, Revolut received conditional approval to establish a national bank in the USA.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Bubblemaps Strengthens Pre-Verification System to Prevent 'Hunter Biden Meme Coin Crash'

How Foreign Institutions View the Diesel Crisis in September: Crack Spreads, Cost Transmission, and Stagflation Risks

Crypto Data Sent to Tax Authorities: Paymium and Bull Bitcoin Rejected

Bitcoin’s newest mobile privacy feature can make your incoming money completely invisible

Did LayerZero lose the private key that allows the creation of stablecoins for the State of Wyoming?

AI and the extinction of humanity: the $2 trillion danger?

18 Attorneys General Oppose Clarity Act Ahead of Key Senate Vote

From Concrete to Compute: Why Clichmont Is Building AI Infrastructure Instead of Renting It

NBIS Stock Faces a $200 Billion Funding Gap: Is Nebius Growing Too Fast?

Why Circle Is Building Its Own Blockchain? A Complete Breakdown Before the Arc Mainnet Launch

Digital Renminbi, Changed

Trump Opposes Strengthening AI Regulations, Emphasizes Technological Competition

45 Cryptocurrency Wallets in the App Store Put Users' Funds at Risk

Bankless's Successful Methodology for Portfolio Reallocation: How to Identify Undervalued Tokens from VVV to Hyperliquid?

Turing Quantum Releases TuringQ Gen3 Photonic Quantum Computer

The New Crypto Tycoon’s Gold Rush: Coinbase Co-Founder’s Venezuelan Oil Field Adventure

Ruthnick Reveals $250 Million Income... The Connection Between Tether, Cantor, and His Children Comes to Light

Planned Financial Crisis: the new global monetary architecture of the dollar

Morpho Proposes Transition of Mini App Operations to Feather

Dialogue with Fejau: The Next Round of the Bull Market for Digital Assets is Finally Here

Real Review of World.xyz: Millisecond Trading and Betting Against Market Makers

CLARITY Act After September 15: Three Scenarios for How Crypto Markets Could React
Three different outcomes could follow September 15's vote and the market reaction depends less on pass or fail than on which specific version actually happens.

Ethereum Tentatively Sets Test Implementation Date for Glamsterdam

Teacher's Day: How Much Teachers Earn in Argentina and Which Province Pays the Best

ZEC Rises into the Top Ten, Old Controversies Resurface

Canadian Financial Authority Treats Tokenized Deposits as Equivalent to Traditional Deposits

Solana Launches Prediction Market Amid Technical Hurdles

Dark energy may be changing, according to a study of 3,000 supernovae

Rising Oil Prices Recalibrate the Landscape for Argentine Investors: Which Alternatives Are Gaining Ground









