YFarmX

Crypto NewsSecurity

Revolut disclosed customer identity and Bitcoin records after a fraudulent government request

Revolut's customer notice describes a fraudulent request from a mailbox inside a government domain, with identity documents and transaction records potentially disclosed.

Editorial illustration of a passport, a government-request envelope and a Bitcoin coin beside the Revolut name.

Revolut says it released customer information in response to a fraudulent government request. Its notice, published by recipient Mark Karpelès on 12 September, lists passport or driving-licence copies, verification selfies and financial records, including Bitcoin transactions, among the information potentially disclosed.

How did the request appear legitimate?

According to the notice reproduced by Karpelès, the sender used an unauthorised email account created within an official government authority’s domain. Revolut says the communication carried genuine domain-authentication credentials and was treated as an authentic request.

Email authentication can establish that a message came through a domain’s infrastructure, while the authority of the person making the request still requires a separate check.

Revolut says it subsequently contacted the agency independently, alerted it to the unauthorised account, blocked the address internally and began notifying relevant regulators. It also says it applied protective measures for affected customers.

Excerpt of Mark Karpelès’s original post reproducing Revolut’s customer notice.
Revolut’s notice reproduced by Mark Karpelès on X, captured 12 September 2026. Source. Select the image to enlarge.

Which information was involved?

The notice uses conditional wording for the individual records affected. Its categories cover:

Category Information listed
Identity and contact Name, birth date, occupation, postal address, email and phone number
Verification Identity-document copy and onboarding selfie
Financial activity Account statements, IBAN, account details, withdrawals and transaction history, including Bitcoin

Revolut distinguishes the verification photograph from biometric facial telemetry, which it says was excluded. The notice leaves the customer count and the government agency’s identity unspecified.

Bitcoin records connect identity with financial activity

Records linking a named person, a home address and crypto activity can make an impersonation attempt much more convincing. A caller may be able to repeat genuine account details while asking the customer to take an unsafe action.

In a public response, Kraken security executive Nick Percoco described the requests as targeted and warned affected recipients about increased physical-security risk. That is his assessment of the disclosure; possession of the records alone does not establish a subsequent attack.

Revolut’s own scam-guidance webpage with its security illustration.
Revolut’s customer guidance page, published 7 May 2021. This is general guidance, separate from the incident notice. Source. Select the image to enlarge.

Verifying a suspicious approach

Revolut’s fraud guidance directs customers to the in-app chat when a call or message appears suspicious. Opening the app independently gives affected customers a direct route to verify the notice and ask which of their records were supplied.

Sources

  1. Mark Karpelès: customer notice reproduced in fullx.com
  2. Nick Percoco: assessment of the targeted data requestsx.com
  3. Revolut: recognising suspicious calls and messagesrevolut.com