Revolut confirms encountering complex identity forgery attack against high-net-worth users
According to TechCrunch, financial technology giant Revolut confirmed on September 12 that an unauthorized external third party used the email domain name of a legitimate government agency to submit a fraudulent information request. This incident led to the disclosure of some customers 'identity documents and Bitcoin transaction activity records.
The London-based financial technology company said only a "limited" number of its more than 800 million users had been affected. The company described the incident as an elaborate external identity forgery scam.
Details of the leaked data
According to notification emails sent to affected customers and reviewed by TechCrunch, the leaked data includes identification and contact information such as birth dates, postal addresses, email addresses and phone numbers, as well as copies of identification documents such as passports and driver's licenses. In addition, the information may also include verification selfies, account statements, and transaction data.
Online investigator ZachXBT, who posted the relevant post late Friday, pointed out that the leak appeared to be mainly aimed at high-net-worth users. Recorded Bitcoin activity is linked to real-world identities and home addresses.
Revolut's response
A spokesperson for Revolut told TechCrunch: "Revolut recently discovered a complex external identity forgery scam in which an unauthorized third party used the domain mailbox of a legitimate government agency to submit fraudulent information requests."
The company said that after discovering the scam, it had blocked the email address and notified relevant government agencies, law enforcement and regulatory agencies. The company added: "Revolut's systems and client funds were not affected."
Revolut did not disclose the specific number of people affected, nor did it say whether the incident was limited to specific markets or which specific government agency was involved.
Why this is crucial for cryptocurrency users
This incident shows that social engineering attacks-not technical vulnerabilities-are enough to cause Bitcoin holders on the platforms of mainstream financial institutions to lose their anonymity. Revolut is expanding its crypto footprint in the EU and beyond, and recently decided to remove the USDT ahead of the EU Cryptographic Asset Markets Regulation (MiCA) deadline.
The leak also echoes a broader pattern of security incidents affecting cryptography-related services, such as the LayerZero executor wallet leak earlier this year that resulted in the theft of $2.4 million.
Subsequent developments
Currently, the financial technology company has not announced a timetable for further disclosure, and the full disclosure is still unclear. For affected users, the risk of phishing and identity fraud is significantly increased because leaked records match personal documents with transaction history.
Revolut stated that it had contacted the affected customers directly and that the matter was still under review by the relevant authorities it notified.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC