Revolut said it disclosed customer identity and financial records after responding to a fraudulent request that appeared to come from a government agency. According to a customer notice shared by on-chain investigator ZachXBT, the sender used an official agency email domain and the message passed authentication checks, leading the company to treat it as legitimate.
The material described in the notice included personal details, copies of identity documents, verification selfies, account statements and full transaction histories. Bitcoin wallet reference numbers were listed among the information contained in statements, and Revolut said withdrawal records and Bitcoin transactions were also part of what was provided.
A request that appeared genuine
The notice says the message was sent from an unauthorized account using a real government agency domain, rather than a lookalike address. Revolut said the communication carried valid domain authentication credentials and was fulfilled under what it described as a reasonable belief that the request was authentic.
The agency involved was not identified in the portion of the notice that was made public. The notice also did not explain how the unauthorized sender gained use of the agency’s email domain, and it gave no date for when the request was received or when the disclosure took place.
Based on the wording shown, the incident was an unauthorized disclosure in response to a deceptive request. The notice did not say an attacker entered Revolut’s systems, accessed customer accounts directly or removed funds.
What data Revolut says was disclosed
Revolut listed full names, dates of birth and occupations among the identity details handed over. It also said postal addresses, email addresses and telephone numbers were included.
The company said copies of identity documents such as passports or driver’s licences were disclosed, along with verification selfies submitted during checks. Revolut distinguished those images from biometric facial telemetry data, which it said was not involved.
The notice further said account statements, IBANs, account status, account-opening dates, Bitcoin wallet reference numbers, withdrawal records and full transaction histories were provided. It described categories of information that may have been disclosed, but did not establish that every affected customer had every type of record on file.
Unclear scope, but possible targeting
ZachXBT said multiple customers received an alert email on Friday, Sep. 11. However, neither his post nor the visible portion of the notice gave a confirmed number of affected users.
He also said the incident appeared limited in size and may have targeted high-net-worth users. Revolut’s notice, as shown publicly, did not confirm either point or explain how any customers may have been selected.
The company serves more than 80 million customers globally, according to an August announcement. That figure refers to Revolut’s overall user base and does not indicate how many people were affected by this disclosure.
Risks and the next known facts
The information listed in the notice could create identity theft, fraud or financial-loss risks, depending on what was disclosed in each case. The publicly shared material did not document any confirmed misuse of the records after the incident.
The screenshot also did not say whether Revolut had notified a regulator or when the company first became aware of the unauthorized request. UK data-breach guidance says certain personal data breaches should be reported within 72 hours where feasible, and affected individuals should be told without undue delay when the risk is high.
The incident comes as Revolut continues to expand its banking and digital-asset services, though those efforts are separate from the disclosure. Based on the material made public so far, the next confirmed step is customer notification; key details including the agency’s identity, the number of affected users and any regulatory follow-up remain undisclosed.
Source: crypto.news