Revolut confirms that some customers 'sensitive information was leaked due to fraudulent government domain name requests.
On September 13, digital bank Revolut stated that sensitive information of a small number of customers was disclosed due to an unauthorized party using an email account with a legitimate government agency domain name to send fraudulent data requests. According to The Block, the company has notified affected customers, regulators and law enforcement.
Fraudulent government domain name request triggers data breach
Revolut pointed out that the request appeared authentic because it came from an unauthorized mailbox created within the domain name infrastructure of an official government authority and carried authentic domain name certification certificates. Subsequently, the company determined that the sender's request was fraudulent. Revolut stated that after identifying the issue, it had blocked the relevant address and notified the affected party.
The leak records contain KYC files and Bitcoin transaction history
According to the Revolut customer notification forwarded by Mark Karpelès on the X platform, the information that may be leaked includes identification documents, verification selfies, address, IBAN (International Bank Account Number), account statements, withdrawal records and complete transaction history, including Bitcoin transaction records.
As a result, the leak may combine Know Your Customer (KYC) records with customer account activity information. Revolut's notice only stated that there was a potential risk of disclosure of the information, and did not publicly specify which types of information would apply to each affected customer.
The scale and identity of the organization involved have not been announced
As of September 12, Revolut has not announced the exact number of customers affected, nor has it confirmed the specific government agencies involved in the domain name infrastructure, nor has it provided a detailed timeline for the leak, which The Block reported.
Revolut emphasized that its systems are operating normally and customer funds have not been affected. In its public statement, the company characterized the incident as a fraudulent data disclosure request rather than an intrusion into its systems, but did not provide further details on the scale of the institutions or customers involved.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC