Key Highlights
- A spoofed government email successfully tricked Revolut into releasing sensitive customer information, including Bitcoin transaction records
- The fraudulent message originated from an authentic agency email domain and successfully cleared domain authentication protocols
- Compromised information ranged from personal identifiers like names and birth dates to passport scans and identity verification photos
- Financial details such as Bitcoin wallet identifiers and complete transaction logs were among the leaked materials
- Blockchain researcher ZachXBT indicated the breach scope seems contained and potentially focused on affluent account holders
The fintech platform Revolut inadvertently released confidential customer information to an illegitimate recipient following what appeared to be an authentic government data request. The fraudulent communication utilized a genuine government agency email address and successfully navigated standard domain verification protocols.
Revolut processed the data request under the assumption it was legitimate. The company has remained silent regarding which specific agency’s domain was compromised or the method by which unauthorized access was obtained.
Detailed Breakdown of Compromised Information
The unauthorized disclosure encompassed extensive personal and financial details. Customer identifiers including complete names, birth dates, professional occupations, residential addresses, email contacts, and telephone numbers were all included.
Government-issued identification materials such as passports and driving permits were transmitted, alongside photographic selfies that customers provided during account verification procedures. The company emphasized that biometric facial mapping information remained secure.
Banking records constituted a substantial portion of the leaked data. Documents including account statements, International Bank Account Numbers, account creation dates, fund withdrawal logs, and comprehensive transaction timelines reached the unauthorized recipient.
Bitcoin wallet identification codes were visible within these banking statements. Complete Bitcoin transaction chronologies were similarly disclosed, creating potential privacy concerns for cryptocurrency users whose financial behaviors can now be connected to their real-world identities.
The company confirmed that cryptographic private keys, login credentials, and complete payment card information were excluded from the data breach.
Scope of Affected Customers
Blockchain analyst ZachXBT published the customer notification via Telegram on September 11. His assessment suggests the incident affected a restricted number of users and may have specifically targeted wealthy account holders. Revolut has declined to specify the exact customer count impacted.
The platform’s global user base exceeds 80 million customers. This figure represents total platform users rather than those impacted by this particular security incident.
The customer alert provides no clarification about whether every affected user had all mentioned data types on file, nor does it explain the selection criteria.
Compliance and Security Implications
According to the UK Information Commissioner’s Office, data security failures can result in identity fraud, financial scams, and monetary damages. Regulatory frameworks mandate organizations report qualifying breaches within a 72-hour window and inform impacted individuals without undue delay.
The notification image distributed by ZachXBT does not indicate whether Revolut filed regulatory reports or specify when the company discovered the fraudulent nature of the request.
Beyond the customer notification, Revolut has issued no public statements regarding this incident. The organization has similarly withheld information about which agency’s email infrastructure was exploited.
This security lapse occurs amid Revolut’s business growth initiatives. The company obtained provisional approval for United States banking operations from the Office of the Comptroller of the Currency on September 3. Additionally, it introduced EURR, its euro-pegged stablecoin, to select European customers during August.
These business developments remain unconnected to the data disclosure incident. Revolut has not identified any US-based users among those affected by the breach.





