Researchers Uncover Scheme of Fake Crypto Requests in Revolut
- Analysts have discovered how Revolut transmitted customer data through fake requests.
- The incident centered not on a breach of the banking application itself, but on the abuse of the channel through which financial institutions interact with government bodies.
- 680 Revolut customers may have been affected by the leak.
- According to researchers, the attackers used public crypto transactions and wallet addresses to obtain KYC data of potentially wealthy users.
The fintech company Revolut is facing the consequences of a data leak affecting around 680 customers after attackers used compromised Italian government email accounts to send fake requests to the fintech company. This is reported by FT and International Cyber Digest.
‼️ BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments.
They say the operation targeting Revolut ran for six months, and that they used Italian law... pic.twitter.com/ZYGWZEc0tL
--- International Cyber Digest (@IntCyberDigest) September 14, 2026
In light of the publication of user data and possible ransom demands, researchers are revealing the mechanics of the attack, while lawyers and human rights advocates point to a systemic issue in verifying government requests in the financial sector.
Additionally, some claims are being disseminated by the alleged attackers themselves. Revolut has not confirmed all the disclosed figures and details.
Revolut disclosed customer data through a fraudulent request --- among them, the history of Bitcoin transactions
13.09.2026
Read
According to early Revolut investor and independent analyst Max Karpis, the company has received ransom demands, and individuals claiming to possess the stolen files have begun posting copies of documents and selfies of customers on Telegram.
After Revolut's data breach, the company has reportedly received ransom demands: pay up, or they'll release customer files.
People claiming they hold the pack are posting ID copies and selfies on Telegram and saying they will drip more every day. One figure doing the rounds is...
--- Max Karpis (@maxkarpis) September 14, 2026
At the same time, Karpis emphasized that the claimed amount of 10,000 BTC has not been confirmed by Revolut, and the information should be taken with caution.
*<<Revolut still claims a "limited" scale of the incident, and the app and funds were not hacked. This is extortion after a Revolut employee transmitted KYC to an unauthorized email address on a legitimate government domain. Payment would not return passports>>, he wrote.
Karpis also urged potentially affected users to take additional security measures: if possible, freeze credit lines, set a new access code and transaction alerts in the app, and avoid contact with individuals who already know the user's IBAN or previous cryptocurrency transactions.
Separately, he advised considering the possibility of replacing passports, as in some countries, after document compromise, one can cancel the old number and obtain a new one. Meanwhile, the expert warned of another potential fraud scheme: offers to "delete the file" for money may be attempts at re-extortion.
How attackers could obtain cryptocurrency client data
According to a user of platform X under the account Korra, a hacker using the alias IAmNotAVillain employed a so-called "spray and pray" tactic: sending Revolut hundreds of cryptocurrency transaction IDs and deposit addresses and requesting information about the associated accounts.
‼️ BREAKING: Duel can report that the Revolut hacker used a "spray and pray" strategy, sending hundreds of cryptocurrency transaction IDs to Revolut and asking for the associated account details. Revolut complied.
This explains the sheer volume of data the hackers were able to... pic.twitter.com/RqGsuEIkMZ
--- Korra (@korraflow) September 15, 2026
According to Duel, such requests were sent under the guise of a forged European Investigation Order. Revolut allegedly provided archives containing client data in response.
Researchers stated that they received and verified authentic copies of emails in .eml format. One of them contained 10 folders, each dedicated to a specific client. According to Duel, the folders contained:
- photos of identity documents;
- selfies for verification;
- account information;
- unedited transaction data.
The password for the encrypted ZIP archive, according to researchers, was sent in a separate email.
This scheme also explains why the attackers could specifically target information about wealthy Revolut clients. Public blockchains allow visibility of addresses and transactions, thus a cryptocurrency transaction could be used as a sort of search key for requests to a centralized financial institution.
Researchers claim that the hacker sent Revolut hundreds of transaction hashes and deposit addresses that he believed were linked to high-asset clients. After that, the company allegedly returned information about the relevant users.
Separate claims about 147 GB of data allegedly stolen from Italian government systems, as well as the publication of client data, are being circulated by researchers and individuals claiming to be in contact with the attackers.
Human rights advocate and president of the Open Dialogue Foundation, Lyudmyla Kozlovska, noted that new documents confirm that on July 24, 2026, Revolut refused to directly disclose information in response to a request covering 198 hashes. According to her, 169 of them were related to Revolut Ltd in the UK, while another 29 were linked to a Swiss legal entity.
New evidence shows: (1) @Revolut did apply the one refusal ground the law gives it. (2) the attackers targeted in their malicious request high-value clients using blockchain transactions.
Documents show that on 24 July 2026, on a request covering 198 hashes, Revolut refused... https://t.co/Hs4eHdvBuo
--- Lyudmyla Kozlovska 🇪🇺🇺🇦 (@LyudaKozlovska) September 15, 2026
According to Kozlovska, the company applied the legal ground for refusal—jurisdictional limitation. The request only concerned accounts at Revolut Bank UAB in Lithuania, while for other cases, the applicant was directed to the British mutual legal assistance procedure.
At the same time, she emphasized that European anti-money laundering rules do not impose a separate obligation on banks to verify the authenticity of the party behind an authenticated state request.
<
>, Kozlovska stated.
What Victims Should Do and Why the Incident Has Broader Implications
Kozlovska urged European citizens to contact their Members of the European Parliament and demand urgent hearings on the use of mass collection of financial data as a tool for attacks.
She also pointed out a potentially broader issue: a similar risk may apply to banks, cryptocurrency exchanges, and payment services in jurisdictions where FATF rules and relevant AML legislation are in effect.
According to her, financial institutions are required to respond to properly formatted government requests, while the mechanisms for verifying who is actually behind such requests may be limited.
Kozlovska noted that the issue has already been raised before the European Parliament by human rights organizations, victims, and experts with the support of the Open Dialogue Foundation. She highlighted that this year the European Parliament, in a resolution dated June 18, 2026, specifically marked the risk of transnational financial repression.
At the time of writing, Revolut had not published specific recommendations for customers regarding further actions related to the incident on its page on X.
It is worth noting that recently, Revolut received conditional approval to establish a national bank in the USA.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Kraken parent plans regulated Hyperliquid perps

Phemex CEO Federico Variola: The AI Wave Has Drained Significant Cryptocurrency Funds and Enhanced Hacking Capabilities

Insight WEEX: CLARITY Act Explained as Bitcoin Tests the $75K Level

Once Valued at $7 Billion, Veteran DeFi Project Decides to Shut Down

KRPT and Inter Motto Join Forces for the Growth Journey of Crypto Companies

Coinbase, Robinhood, and Circle: Three Issuers, the Same Distribution Dilemma

Malaysia crypto trading tops $4B, Fitch says

2027 Budget: Economists See "Reasonable" Inflation, but Doubt 4% GDP Growth

SWIFT Shared Ledger Goes Live: Why Tokenized Deposits Are Moving to Institutional Payment Front

Tarabut Secures $50 Million for Embedded Finance Expansion in Saudi Arabia

Delphi Digital: The Bottleneck of the Agency Economy Is Not Payment, But 'Delivery and Acceptance'

Arc Launches on Its First Day, Crypto Infrastructure Projects Celebrate, Is the Next Robinhood Chain Here?

Ripple CEO says crypto growth won’t hinge on CLARITY
Why WEEX Keeps Showing Up at TOKEN2049: Inside WEEX's Global Event Journey (2024–2026)
From Dubai to Bali to WEEX TOKEN2049 Singapore: see the full story behind WEEX's 2024–2026 global event journey and why the brand keeps showing up.
Meet WEEX at TOKEN2049 Singapore: What to Expect at the WEEX Booth
Meet WEEX at TOKEN2049 Singapore's WEEX booth, Oct 6–8. See the ISO 27001 reveal, new product news, and on-site activities to expect this year.

FCA Considers Special Rules for Tokenized Gold, Exemptions from Fund Regulations in Sight
WEEX TOKEN2049 Singapore 2026: WEEX Returns as Platinum Sponsor
WEEX returns as Platinum Sponsor of WEEX TOKEN2049 Singapore 2026, Oct 6–8 at Marina Bay Sands. See what to expect at the WEEX TOKEN2049 booth.

Is Polymarket Trading Considered Gambling Under Criminal Law?

Can 龙虾 Coin Reach $0.25 After Its 100x WEEX Rally?
![[Field ③] Shin Geun-young, Chairman of the Village: "Even if the platform disappears, relationships remain"... targeting the global market with 18 business models](/public-static/21_2c30f7df62.png?format=avif)
[Field ③] Shin Geun-young, Chairman of the Village: "Even if the platform disappears, relationships remain"... targeting the global market with 18 business models

Anthropic Pre-IPO Market Heats Up, Entropy Reshapes CEX Liquidity Landscape

Who Benefits from the 20% Separate Taxation on Cryptocurrencies? BCCC Taxation Committee Points Out

Bubblemaps Strengthens Pre-Verification System to Prevent 'Hunter Biden Meme Coin Crash'

Trade Daily, Win Daily: How to Share 5,000 USDT and Compete for iPhone Duo on WEEX

Bitcoin and Ethereum ETF Outflows in September 2026: Are Investors Starting to Withdraw Funds? - Fintech World

Is the First Rate Hike of the 'Warsh Era' Coming? Wall Street Has Calculated Three Scenarios

A $100 million launch balance doesn’t mean a crypto ETF has real investors

Bitcoin: Should We Be Worried? Possible Declines Ahead

BitMart opens user engagement portal as advisers assess withdrawal plans





