Revolut disclosed customer identities and financial records, including Bitcoin transaction histories, after responding to a fraudulent request that appeared to come from a government agency. The request originated from an unauthorized email account using an official agency domain and passed standard domain authentication checks.
According to a customer notice shared by on-chain investigator ZachXBT, Revolut believed the request was genuine and provided the information. The incident appears limited in scope and may have targeted high-net-worth users.
The Drivers of This Incident
An unauthorized sender leveraged access to an official government agency email domain, producing a message that carried valid authentication credentials and therefore bypassed typical verification filters. Revolut processed the request under the assumption it was legitimate, releasing personal details, identity documents, verification selfies, account statements, IBANs, withdrawal records, and full transaction histories that included Bitcoin wallet references and activity. For perspective, the company has emphasized that biometric facial telemetry data was not involved, and the notice lists categories of potentially disclosed information without confirming that every record type applied to every affected customer.
It is important to note the fundamental difference between a direct system breach of Revolut’s infrastructure and a successful social-engineering or domain-based impersonation that caused the firm to voluntarily share data in response to what looked like an official legal request.
Impact and Broader Context
Affected users face elevated risks of identity theft, targeted phishing, and the permanent linkage of verified personal identities to on-chain Bitcoin activity, which cannot be reversed once exposed. This development sparks important discussions about how fintech and crypto platforms handle government data requests, the robustness of email domain authentication, and the privacy implications of KYC-linked crypto transaction records. Supporters of Revolut’s response may note the company’s prompt customer notifications and clarification that core biometrics were not shared. Critics highlight the severity of releasing passport copies, selfies, and complete financial histories, especially for high-value users, and question internal verification processes for high-stakes requests. Analysts observe that such incidents underscore the growing sophistication of attacks that exploit trusted official channels rather than purely technical vulnerabilities.
Customers are advised to monitor for follow-up social-engineering attempts and review their account activity. This analysis is based on the Revolut customer notice shared by ZachXBT and reporting from crypto.news and related outlets for accuracy and reliability. The full number of affected users and any further details remain subject to ongoing investigation.
