Revolut disclosed some customers 'identity information and financial records for forging a request from a government agency.
Digital bank Revolut disclosed some customers' identity information and financial records, including Bitcoin transaction history. The data breach stems from the company's handling of a fraudulent request that appeared to be from a government agency.
Summary of the incident
Revolut stated that an unauthorized sender used the email domain name of an official government agency to send the request. Records disclosed include identification documents, selfies for verification and complete transaction history. In the notification sent to customers, the Bitcoin wallet reference number is listed on the account statement.
Online investigator ZachXBT pointed out that the impact of the incident appears to be limited and may mainly target high-net-worth users.
Attack methods and verification process
According to a Revolut customer notification shared by ZachXBT on Telegram, the request originated from an unauthorized email account using the domain name of an official government agency. The message passed a domain name authentication check, and Revolut said it believed the request was authentic when providing the information.
The notice did not specify the specific institution involved, nor did it explain how unauthorized senders obtained access to their mailbox domain name. In addition, the notice did not mention a specific date of the request or disclosure. ZachXBT said that multiple customers received alert emails on Friday, September 11, but neither he nor the notification section displayed in his posts gave a number of confirmations from affected users.
In Revolut's description of the incident, because the email carried valid domain name authentication credentials, it looked like a legitimate government request. The request was sent directly from an unauthorized account using the agency's official email domain name, rather than a fake email disguised as a similar address.
"Given that the communication carried valid domain name authentication credentials, the company complied with the requirement in the reasonable belief that it was requested by a real government agency." The notice read.
This wording describes unauthorized disclosure of data in response to a fraudulent request. The notice clearly stated that the intruder did not access Revolut's system, access customer accounts, or withdraw funds. The notice did not identify the sender and did not state whether relevant agencies had investigated the abuse of his email account.
Details of the information disclosed
Revolut lists the identification information provided including the client's full name, date of birth and occupation. Contact information includes postal address, email address and phone number.
The request also resulted in the disclosure of copied identification documents (such as passports or driver's licenses) and selfies provided by customers for identity verification. Revolut distinguished the images from biometric facial telemetry data it said was not involved.
Account statements constitute another part of the disclosed material. According to the notification, the statement contains IBAN (International Bank Account Number), account status, opening date and Bitcoin wallet reference number. Withdrawal records and a complete transaction history (including bitcoin transactions) are also provided.
The notice lists the types of information that may be disclosed, but does not establish that each affected customer has all types of records. At the same time, the notice did not state whether the wallet private key, account password or complete bank card details were included. Bitcoin transaction history is particularly critical to crypto users because notifications indicate that these records were sent to unauthorized recipients along with names and other account records.
According to Revolut's August announcement, it has more than 80 million customers worldwide. This figure reflects the size of its business rather than the number of users affected by this breach.
Potential impact on affected customers
The UK's Information Commissioner's Office (ICO) said possible consequences of personal data breaches include identity theft, fraud and financial loss. Its leak guidelines require an assessment of the information involved and an analysis of the harm individuals may suffer; but the guidelines do not establish that anyone has suffered such consequences in the Revolut incident.
For customers whose identity documents and transaction records were compromised, the notification indicates that the recipient may have obtained a detailed overview of the person's financial situation. ZachXBT's claim that wealthy users were targeted was not confirmed in the material presented by Revolut, which did not document subsequent abuse of the data.
Regulators 'guidance also stipulates that organizations must, where feasible, report certain personal data breaches within 72 hours of becoming aware of them, and notify individuals without undue delay when they pose a high risk to their rights and freedoms. The screenshot does not say whether Revolut has notified regulators or when the company first learned of the unauthorized request.
In its U.S. security guidelines, Revolut tells customers to use in-app support for Chat features to verify that suspicious contacts are authentic. The company said it would not ask customers to share verification or security codes over the phone. No such code was reported to have been leaked in customer notices displayed by ZachXBT.
Revolut's U.S. operations and cryptocurrency operations
This incident occurred while Revolut was expanding its banking and digital asset services. According to reports, on August 26, the company began providing its euro-anchored stablecoin EURR to some customers in Denmark, Poland and Portugal, and plans to further promote it in Europe. The launch of stablecoins has nothing to do with customer records leaks.
Although the notice did not identify any affected customers as located in the United States, Revolut's U.S. program provides background information to U.S. readers. On September 3, the company received conditional approval from the Office of the Comptroller of the Currency (OCC) for its Bank of America. Its proposed Stanford Bank of Connecticut will receive approximately $95 million in initial capital and is expected to open in 2027 if remaining approval is received.
Currently, according to early reports, Revolut provides U.S. banking services to customers through Lead Bank. The proposed national bank still needs to obtain deposit insurance from the Federal Deposit Insurance Corporation (FDIC), approval from the Federal Reserve and final authorization from the OCC before it can officially open.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC