TheCryptoNewsHub

Decrypt: Revolut reportedly sent passports and Bitcoin histories to fake agency

The fintech firm fulfilled a bogus information demand from a state body's mail domain, per the report.

AI summary availableMarket impact · neutral
By The Crypto News Hub News Desk · September 12, 2026 · · 7 min read
Photo: DS stories · Pexels

On September 12, 2026, Decrypt published a report about Revolut, a fintech company. The publisher stated that the firm fulfilled a fraudulent information request. The request allegedly originated from a government agency's own email domain.

The stake is user privacy. Passports and full Bitcoin transaction histories were exposed for a limited number of users. The incident remains officially unconfirmed according to the desk summary.

The Decrypt report

Decrypt reported on September 12, 2026, that Revolut faced a data exposure. The publisher described a fintech company fulfilling a fraudulent information request. The report carries a timestamp of 17:01:04 UTC on that date. The outlet attached the story as the sole source.

The fraudulent request

The request was fraudulent according to Decrypt. It masqueraded as a government agency inquiry. The fintech firm reportedly treated it as valid. This led to the release of user files. The act is labeled fulfilled in the desk summary.

The email domain element

The fraudulent request came from a government agency's own email domain. Decrypt stated that the sender used that domain. This suggests the message appeared internal to a state body. The domain element is central to the fake nature. No agency name was provided in the facts.

Identity papers exposed

Passports were among the leaked items. Decrypt reported that ID documents left the company. The papers belong to a limited number of users. The exact count remains unreported. The documents are described as exposing identity.

Bitcoin transaction records

Full Bitcoin transaction histories were exposed per the report. Decrypt noted that crypto transaction histories were part of the dump. The records include movements of the asset bitcoin. The histories are described as full. No partial logs were mentioned.

Broader crypto histories

The leak also covered general crypto transaction histories. Decrypt used the term crypto to extend beyond Bitcoin. The fintech firm reportedly sent these logs. The data set included crypto transaction histories for the limited users. The scope stayed limited.

Limited user impact

Only a limited number of users suffered exposure. Decrypt qualified the scope as limited. The report did not name a precise figure. The fintech company is the source of the disclosure. The user set is not publicly detailed.

Fintech classification

The desk summary labels Revolut a fintech company. This places the incident in the financial technology sector. The firm handled identity and crypto data. The classification comes from the provided summary. No exchange label is given.

Technology and security angle

The story type is listed as technology and security. This frames the event as a protocol and data defense issue. The fraudulent request exploited a disclosure process. The security tag applies per the facts. The technology tag also fits.

Confirmation status

Officially confirmed: no. The desk confidence is 21 out of 100. Decrypt published the claim without official confirmation. Readers should treat the report as unverified. The low confidence marks the uncertainty.

Publication timeline

The timeline anchors the report at 2026-09-12T17:01:04+00:00. Decrypt is the sole attached source. No other outlet is listed. The date is the only chronological marker. The time is UTC.

Asset involvement

Bitcoin is the only named asset in the facts. The transaction histories reference this coin. No other tokens are explicitly stated. The asset link is direct. The crypto term covers the broader set.

No listed organizations

The story facts record no organizations beyond the implied agency. The government agency is not named. This limits attribution. No protocol is recorded. The known data omits extra bodies.

No people recorded

The facts list no individuals. No person is quoted. Expert context is absent. The report stands without named sources inside the company. The desk notes no people.

Market impact read

The desk marks market impact as neutral. This indicates no price effect asserted. The BTC reference does not alter the read. The neutral tag is from the summary. No market context section is required.

The disclosure mechanism

The fintech company fulfilled the request. That means it provided the data. The request was fraudulent. The fulfillment occurred despite the fake nature. The process failure is central.

The limited number phrase

The desk summary uses the word limited. This modifies the number of users. The exact number is unknown. The report avoids a specific count. The limitation is a key qualifier.

The government agency domain

A government agency's own email domain sent the request. This is a notable detail. The domain belonged to the agency. The fraud used that trusted source. The email element is explicit.

The information request type

The request sought information. It was an information request per the summary. The fintech firm answered it. The data included ID and crypto logs. The type is fraudulent.

The crypto transaction histories

Crypto transaction histories were exposed. These are full histories. They include Bitcoin. The limited users had their records sent. The histories are complete per Decrypt.

The passport leak

Passports are identity documents. They were leaked. The fintech company exposed them. The limited users lost passport data. The leak is reported by Decrypt.

The unconfirmed nature

The story is not officially confirmed. Decrypt reported it. The confidence is low. The facts carry the unconfirmed tag. The report remains a claim.

The source attribution

Decrypt is the publisher. It reported the event. The timeline cites Decrypt. The source is attached. No second source appears. The attribution is single.

The desk summary text

The desk summary states the fintech company fulfilled a fraudulent request. It sent from a government domain. It exposed ID and crypto histories. The users were limited. The summary matches the report.

The technology security tag

The story type combines technology and security. This indicates a systems breach. The fake request is a security event. The technology aspect covers data handling. The tag is explicit.

The neutral market read

Market impact read is neutral. This means no market move claimed. The bitcoin asset is named. The price is not discussed. The neutral stance is from the desk.

The confidence score

Desk confidence is 21/100. This is low. The score reflects uncertainty. The unconfirmed status aligns. The number is from the facts.

The timestamp detail

The report time is 2026-09-12T17:01:04+00:00. This is the publication moment. Decrypt posted then. The UTC zone is given. The date is mid-September 2026.

The user count limit

Limited number of users is the phrase. It caps the impact. The precise count is absent. The limit is reported. The users held crypto histories.

The document exposure

ID documents were exposed. Passports are a type. The exposure is full. The fake request caused it. The documents left the firm.

The bitcoin history scope

Bitcoin transaction histories are full. They show all moves. The asset is bitcoin. The histories went to the fraudster. The limited users are affected.

The fake government request

The request is fake. It claimed government origin. The domain matched an agency. The fintech firm complied. The act is reported by Decrypt.

The fulfillment action

The company fulfilled the request. That means it sent data. The request was fraudulent. The fulfillment is the core failure. The action is documented.

The data sent

The sent data included passports. It included Bitcoin histories. It included crypto histories. The set is full. The recipients were fraudulent.

The recipient profile

The recipient posed as government. The email domain was agency owned. The true identity is unknown. The request was fake. The recipient gained data.

The report standing

The report is unconfirmed. It carries low confidence. Decrypt is the sole source. The story type is tech/security. The facts are as given.

The sector label

The firm is fintech. The sector is financial technology. The incident is security. The label comes from summary. No other sector stated.

The asset mention

Bitcoin is mentioned. It is the only asset. The histories reference it. The crypto term broadens. The mention is explicit.

The timeline sole entry

One timeline entry exists. It is Decrypt's report. The time is as above. No other events listed. The entry is immutable.

The conclusion of facts

The reported incident involves Revolut. It leaked data via fake request. The users were limited. The documents were passports. The histories were crypto and Bitcoin. Decrypt reported it unconfirmed.

What it means for the industry

The reported incident shows a fintech firm released identity documents and crypto transaction logs to a fraudulent requester. Per the Decrypt account, this directly exposed passports and Bitcoin histories for a limited user group. The event underscores a disclosure failure within the described process.

Key takeaways

  • Decrypt reported that Revolut fulfilled a fraudulent government-impersonating information request.
  • Passports and full crypto transaction histories were reportedly exposed to the sender.
  • The affected user set is described as limited in the desk summary.
  • The report is not officially confirmed and carries a desk confidence of 21/100.
  • Bitcoin is the only explicitly named asset in the leaked histories.
  • The story is classified under technology and security coverage.

The Decrypt report remains the sole account of the incident. Readers should note the unconfirmed status and low confidence score. Watch for any official statement from Revolut or the unnamed agency. No further timeline entries exist in the provided facts.

Newsroom intelligence

The short version

A fintech company named Revolut reportedly disclosed identity papers and full crypto transaction logs for a limited user set. The disclosure answered a fraudulent request that mimicked a government agency's email, Decrypt reported.

AI-assisted summary · reviewed against the cited reporting

Market snapshot

In this story

How this story developed

  1. createdDecrypt

    Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request

    The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.

Sources & verification

Claim-level citations
  1. 1.On September 12, 2026, Decrypt published a report about Revolut, a fintech company.Decrypt · published
  2. 2.## The Decrypt report Decrypt reported on September 12, 2026, that Revolut faced a data exposure.Decrypt · published
  3. 3.Decrypt reported that ID documents left the company.Decrypt · published
  4. 4.The reported incident shows a fintech firm released identity documents and crypto transaction logs to a fraudulent requester.Decrypt · published

Last verified · Not financial advice. See our editorial policy and risk disclosure.

Questions readers are asking

What did Revolut reportedly leak according to Decrypt?
Decrypt reported that Revolut, a fintech company, fulfilled a fraudulent information request. The leak exposed passports and full crypto transaction histories, including Bitcoin records, for a limited number of users.
Was the Revolut leak officially confirmed?
No. The desk summary marks officially confirmed as no. The report carries a desk confidence of 21 out of 100. Decrypt is the sole attached source for the claim.
How many users were affected by the reported leak?
The facts describe a limited number of users. Decrypt and the desk summary do not provide a precise count. The scope is qualified as limited in the report.
What type of request caused the exposure?
According to Decrypt, the request was fraudulent and sent from a government agency's own email domain. The fintech firm fulfilled it, releasing ID documents and crypto histories.

Story record

Published
Reading time
7 min
Story status
developing
Sourcing
1 publishers · 1 domains
Editorial score
56 / 100
Quality score
81 / 100
revolutpassportsbitcoinfraudulent requestfintechdata exposuredecrypt
News Impact
Impact analysis pending editorial review.
Earn 1 point for reading this article

Sign in and reach the end of the story to qualify. Rewards are awarded server-side after read verification. Rewards Rules.

The daily brief · 07:00 UTC

Signal beyond the noise, once a day

One email with the stories that moved markets, what changed since yesterday, and what our newsroom is watching next.

TC
About the author
The Crypto News Hub News Desk
Editorial Desk

The Crypto News Hub News Desk is our organizational newsroom byline for reports produced from verified public sources using the publication's automated research and quality controls. Reports flagged by those controls — for accuracy, sourcing, high risk or duplication — are held and reviewed by our human editors before publication. This byline does not imply that every piece was individually rewritten or signed off by a named journalist.

Reader feedback

We correct in the open. If something here is wrong, incomplete, or missing context, tell us and we will publish the correction with a version note.

Continue reading