Mt. Gox Former CEO Among Victims in Revolut Breach After Hackers Used Real Government Email
Mt. Gox former CEO Mark Karpelès was among 680 Revolut customers whose data was exposed

Revolut has disclosed the personal and financial information of 680 customers after an unauthorised party used an email account operating within a legitimate government agency's domain to submit fraudulent requests for private data.
The London-headquartered fintech fulfilled the requests because they appeared to come from an official government source. Reporting by Infosecurity Magazine said the emails carried valid technical authentication for the government domain and were processed by Revolut employees as standard legal-compliance requests.
Britain's Information Commissioner's Office (ICO) is investigating the incident after Revolut reported the breach. People claiming responsibility for the attack are threatening to publish the stolen information unless a ransom is paid, though Revolut has not confirmed any ransom discussions. The company said its systems and customer funds were unaffected and that it had contacted affected customers.
Mt Gox Executive Among Affected Customers
Mark Karpelès, the former chief executive of Mt Gox, is among the Revolut customers affected by the breach.
The Financial Times reported that Karpelès received an email from Revolut warning that his personal data may have been compromised. He initially suspected the message was a scam before confirming the breach was genuine.
Karpelès later criticised Revolut's decision to disclose the information, arguing that sensitive customer records should have been subject to additional verification even when a request appeared to come from a verified government address.
The potentially exposed information included cryptocurrency-related data, such as Bitcoin transaction histories, according to Revolut's customer notification.
Identity and Financial Records Exposed
The customer notification said the information disclosed could include names, dates of birth, postal and email addresses, telephone numbers and copies of identity documents such as passports and driving licences. Verification selfies, account statements and transaction histories may also have been exposed.
The Block reported that the notification shared by Karpelès also listed IBANs and withdrawal records, along with full transaction histories.
‼️ BREAKING: The threat actors who targeted Revolut with information-demand emails are now posting sensitive customer data, including that of high-profile clients such as tennis player Shevchenko and Römer, CEO of Gamdom/Skinscom.
— International Cyber Digest (@IntCyberDigest) September 13, 2026
They want Revolut to pay up. They say they'll… pic.twitter.com/obuVOOABx7
Revolut described the incident as a 'sophisticated external impersonation scam', in which an unauthorised third party used a legitimate government agency email domain to submit fraudulent requests for customer information. The fraudulent requests passed technical authentication checks, leading Revolut employees to process them as standard legal-compliance requests, believing them to be genuine.
After discovering the deception, Revolut said it blocked the address and alerted the relevant government agency, law enforcement authorities, data-protection officials and financial regulators.
The company said its systems and customer funds were unaffected. The incident involved the disclosure of customer information in response to fraudulent requests, rather than a reported intrusion into Revolut's core systems.
ICO Investigation Follows Data Disclosure
The Information Commissioner's Office (ICO) has opened an investigation after Revolut reported the incident. The regulator will examine the circumstances surrounding the disclosure and the company's handling of affected customer information.
The Financial Times reported that Revolut had contacted 680 affected customers following its initial investigation. Earlier reports quoted the company as describing the group only as 'very limited' without giving a figure.
Revolut has not publicly identified the government agency whose domain was used in the fraudulent requests or explained how the unauthorised account came to operate within that domain.
The exposure of identity documents, account information and transaction histories could create risks of targeted phishing or identity fraud. The reported threat to publish the information adds a further concern for affected customers.
The ICO investigation is expected to examine how the fraudulent requests were processed and whether additional safeguards are needed to prevent similar disclosures.
© Copyright IBTimes 2026. All rights reserved.
























