Revolut disclosed customer identities and financial records, including Bitcoin transaction histories, after acting on a fraudulent request that carried a government agency's official email domain. The bank said the message passed domain authentication checks, so it believed the request was genuine. On-chain investigator ZachXBT said the incident appears limited but may have targeted high-net-worth users.
Revolut handed over customer identity documents, account statements and Bitcoin transaction histories after a fraudulent request that appeared to come from a government agency, according to a customer notice shared on Telegram by on-chain investigator ZachXBT. The unauthorized sender used the agency's official email domain rather than an address designed to merely resemble it.
How the fake request got through
Revolut said the email carried valid domain authentication credentials, which is why it treated the request as authentic. "it seems to have been targeted at high net worth users", ZachXBT said of the incident. The notice does not name the agency or say how the sender obtained access to its domain.
Multiple customers received an alert email on Friday, Sep. 11, though neither ZachXBT nor the portion of the notice he shared gave a confirmed count of affected users. Revolut's account does not say an intruder entered its systems or withdrew funds — only that it disclosed records in response to the deceptive request.
What data Revolut handed over
The disclosed material included full names, dates of birth, occupations, postal addresses, emails and phone numbers, along with copies of passports or driver's licenses and the selfies customers submitted for identity checks. Revolut said biometric facial telemetry data was not included.
Account statements made up the rest of the disclosure. They contained IBANs, account-opening dates, Bitcoin wallet reference numbers, withdrawal records and full transaction histories, including Bitcoin activity. The notice lists categories of information that may have been shared; it does not establish that every affected customer had every record on file, and it does not indicate that wallet private keys or account passwords were disclosed.
Wider stakes for affected customers
The UK Information Commissioner's Office says the possible consequences of a personal data breach include identity theft, fraud and financial loss, though its guidance does not establish that anyone has suffered those outcomes here. Organizations must generally notify regulators within 72 hours of becoming aware of a breach, and the notice does not say whether Revolut has done so.
Meanwhile, the disclosure lands as Revolut expands its crypto and banking business. Revolut serves more than 80 million customers globally, and on Aug. 26 it began offering its euro-backed EURR stablecoin to customers in Denmark, Poland and Portugal. Separately, it received conditional approval for a U.S. bank from the Office of the Comptroller of the Currency on Sep. 3, with a proposed Stamford, Connecticut charter that could open in 2027.
Sources: crypto.news, Crypto Briefing
Trading involves risk.