On September 12, 2026, Decrypt published a report about Revolut, a fintech company. The publisher stated that the firm fulfilled a fraudulent information request. The request allegedly originated from a government agency's own email domain.
The stake is user privacy. Passports and full Bitcoin transaction histories were exposed for a limited number of users. The incident remains officially unconfirmed according to the desk summary.
The Decrypt report
Decrypt reported on September 12, 2026, that Revolut faced a data exposure. The publisher described a fintech company fulfilling a fraudulent information request. The report carries a timestamp of 17:01:04 UTC on that date. The outlet attached the story as the sole source.
The fraudulent request
The request was fraudulent according to Decrypt. It masqueraded as a government agency inquiry. The fintech firm reportedly treated it as valid. This led to the release of user files. The act is labeled fulfilled in the desk summary.
The email domain element
The fraudulent request came from a government agency's own email domain. Decrypt stated that the sender used that domain. This suggests the message appeared internal to a state body. The domain element is central to the fake nature. No agency name was provided in the facts.
Identity papers exposed
Passports were among the leaked items. Decrypt reported that ID documents left the company. The papers belong to a limited number of users. The exact count remains unreported. The documents are described as exposing identity.
Bitcoin transaction records
Full Bitcoin transaction histories were exposed per the report. Decrypt noted that crypto transaction histories were part of the dump. The records include movements of the asset bitcoin. The histories are described as full. No partial logs were mentioned.
Broader crypto histories
The leak also covered general crypto transaction histories. Decrypt used the term crypto to extend beyond Bitcoin. The fintech firm reportedly sent these logs. The data set included crypto transaction histories for the limited users. The scope stayed limited.
Limited user impact
Only a limited number of users suffered exposure. Decrypt qualified the scope as limited. The report did not name a precise figure. The fintech company is the source of the disclosure. The user set is not publicly detailed.
Fintech classification
The desk summary labels Revolut a fintech company. This places the incident in the financial technology sector. The firm handled identity and crypto data. The classification comes from the provided summary. No exchange label is given.
Technology and security angle
The story type is listed as technology and security. This frames the event as a protocol and data defense issue. The fraudulent request exploited a disclosure process. The security tag applies per the facts. The technology tag also fits.
Confirmation status
Officially confirmed: no. The desk confidence is 21 out of 100. Decrypt published the claim without official confirmation. Readers should treat the report as unverified. The low confidence marks the uncertainty.
Publication timeline
The timeline anchors the report at 2026-09-12T17:01:04+00:00. Decrypt is the sole attached source. No other outlet is listed. The date is the only chronological marker. The time is UTC.
Asset involvement
Bitcoin is the only named asset in the facts. The transaction histories reference this coin. No other tokens are explicitly stated. The asset link is direct. The crypto term covers the broader set.
No listed organizations
The story facts record no organizations beyond the implied agency. The government agency is not named. This limits attribution. No protocol is recorded. The known data omits extra bodies.
No people recorded
The facts list no individuals. No person is quoted. Expert context is absent. The report stands without named sources inside the company. The desk notes no people.
Market impact read
The desk marks market impact as neutral. This indicates no price effect asserted. The BTC reference does not alter the read. The neutral tag is from the summary. No market context section is required.
The disclosure mechanism
The fintech company fulfilled the request. That means it provided the data. The request was fraudulent. The fulfillment occurred despite the fake nature. The process failure is central.
The limited number phrase
The desk summary uses the word limited. This modifies the number of users. The exact number is unknown. The report avoids a specific count. The limitation is a key qualifier.
The government agency domain
A government agency's own email domain sent the request. This is a notable detail. The domain belonged to the agency. The fraud used that trusted source. The email element is explicit.
The information request type
The request sought information. It was an information request per the summary. The fintech firm answered it. The data included ID and crypto logs. The type is fraudulent.
The crypto transaction histories
Crypto transaction histories were exposed. These are full histories. They include Bitcoin. The limited users had their records sent. The histories are complete per Decrypt.
The passport leak
Passports are identity documents. They were leaked. The fintech company exposed them. The limited users lost passport data. The leak is reported by Decrypt.
The unconfirmed nature
The story is not officially confirmed. Decrypt reported it. The confidence is low. The facts carry the unconfirmed tag. The report remains a claim.
The source attribution
Decrypt is the publisher. It reported the event. The timeline cites Decrypt. The source is attached. No second source appears. The attribution is single.
The desk summary text
The desk summary states the fintech company fulfilled a fraudulent request. It sent from a government domain. It exposed ID and crypto histories. The users were limited. The summary matches the report.
The technology security tag
The story type combines technology and security. This indicates a systems breach. The fake request is a security event. The technology aspect covers data handling. The tag is explicit.
The neutral market read
Market impact read is neutral. This means no market move claimed. The bitcoin asset is named. The price is not discussed. The neutral stance is from the desk.
The confidence score
Desk confidence is 21/100. This is low. The score reflects uncertainty. The unconfirmed status aligns. The number is from the facts.
The timestamp detail
The report time is 2026-09-12T17:01:04+00:00. This is the publication moment. Decrypt posted then. The UTC zone is given. The date is mid-September 2026.
The user count limit
Limited number of users is the phrase. It caps the impact. The precise count is absent. The limit is reported. The users held crypto histories.
The document exposure
ID documents were exposed. Passports are a type. The exposure is full. The fake request caused it. The documents left the firm.
The bitcoin history scope
Bitcoin transaction histories are full. They show all moves. The asset is bitcoin. The histories went to the fraudster. The limited users are affected.
The fake government request
The request is fake. It claimed government origin. The domain matched an agency. The fintech firm complied. The act is reported by Decrypt.
The fulfillment action
The company fulfilled the request. That means it sent data. The request was fraudulent. The fulfillment is the core failure. The action is documented.
The data sent
The sent data included passports. It included Bitcoin histories. It included crypto histories. The set is full. The recipients were fraudulent.
The recipient profile
The recipient posed as government. The email domain was agency owned. The true identity is unknown. The request was fake. The recipient gained data.
The report standing
The report is unconfirmed. It carries low confidence. Decrypt is the sole source. The story type is tech/security. The facts are as given.
The sector label
The firm is fintech. The sector is financial technology. The incident is security. The label comes from summary. No other sector stated.
The asset mention
Bitcoin is mentioned. It is the only asset. The histories reference it. The crypto term broadens. The mention is explicit.
The timeline sole entry
One timeline entry exists. It is Decrypt's report. The time is as above. No other events listed. The entry is immutable.
The conclusion of facts
The reported incident involves Revolut. It leaked data via fake request. The users were limited. The documents were passports. The histories were crypto and Bitcoin. Decrypt reported it unconfirmed.
What it means for the industry
The reported incident shows a fintech firm released identity documents and crypto transaction logs to a fraudulent requester. Per the Decrypt account, this directly exposed passports and Bitcoin histories for a limited user group. The event underscores a disclosure failure within the described process.
Key takeaways
- Decrypt reported that Revolut fulfilled a fraudulent government-impersonating information request.
- Passports and full crypto transaction histories were reportedly exposed to the sender.
- The affected user set is described as limited in the desk summary.
- The report is not officially confirmed and carries a desk confidence of 21/100.
- Bitcoin is the only explicitly named asset in the leaked histories.
- The story is classified under technology and security coverage.
The Decrypt report remains the sole account of the incident. Readers should note the unconfirmed status and low confidence score. Watch for any official statement from Revolut or the unnamed agency. No further timeline entries exist in the provided facts.
Newsroom intelligence
The short version
A fintech company named Revolut reportedly disclosed identity papers and full crypto transaction logs for a limited user set. The disclosure answered a fraudulent request that mimicked a government agency's email, Decrypt reported.
AI-assisted summary · reviewed against the cited reporting
Market snapshot
In this story
BitcoinBTC
How this story developed
- createdDecrypt
Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request
The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.
Sources & verification
- 1.On September 12, 2026, Decrypt published a report about Revolut, a fintech company.Decrypt · published
- 2.## The Decrypt report Decrypt reported on September 12, 2026, that Revolut faced a data exposure.Decrypt · published
- 3.Decrypt reported that ID documents left the company.Decrypt · published
- 4.The reported incident shows a fintech firm released identity documents and crypto transaction logs to a fraudulent requester.Decrypt · published
Last verified · Not financial advice. See our editorial policy and risk disclosure.
Questions readers are asking
- What did Revolut reportedly leak according to Decrypt?
- Decrypt reported that Revolut, a fintech company, fulfilled a fraudulent information request. The leak exposed passports and full crypto transaction histories, including Bitcoin records, for a limited number of users.
- Was the Revolut leak officially confirmed?
- No. The desk summary marks officially confirmed as no. The report carries a desk confidence of 21 out of 100. Decrypt is the sole attached source for the claim.
- How many users were affected by the reported leak?
- The facts describe a limited number of users. Decrypt and the desk summary do not provide a precise count. The scope is qualified as limited in the report.
- What type of request caused the exposure?
- According to Decrypt, the request was fraudulent and sent from a government agency's own email domain. The fintech firm fulfilled it, releasing ID documents and crypto histories.
Story record
- Published
- Reading time
- 7 min
- Beat
- Bitcoin
- Story status
- developing
- Sourcing
- 1 publishers · 1 domains
- Editorial score
- 56 / 100
- Quality score
- 81 / 100
Sign in and reach the end of the story to qualify. Rewards are awarded server-side after read verification. Rewards Rules.
Signal beyond the noise, once a day
One email with the stories that moved markets, what changed since yesterday, and what our newsroom is watching next.
The Crypto News Hub News Desk is our organizational newsroom byline for reports produced from verified public sources using the publication's automated research and quality controls. Reports flagged by those controls — for accuracy, sourcing, high risk or duplication — are held and reviewed by our human editors before publication. This byline does not imply that every piece was individually rewritten or signed off by a named journalist.
Reader feedback
We correct in the open. If something here is wrong, incomplete, or missing context, tell us and we will publish the correction with a version note.
