Revolut Falls Victim to Spoofed Government Email, Bitcoin Data Compromised

3 hours ago 27

Key Points

  • Digital banking platform Revolut mistakenly released customer information following a deceptive request masquerading as official government correspondence
  • The fraudulent email originated from a legitimate agency domain and successfully cleared authentication protocols
  • Compromised information included personal identifiers, passport documentation, verification photographs, and financial statements
  • Bitcoin wallet identifiers and complete cryptocurrency transaction records were among the leaked materials
  • Blockchain investigator ZachXBT indicated the breach scope appears contained and potentially focused on affluent account holders

The financial technology company Revolut inadvertently shared sensitive customer information with an illegitimate recipient following receipt of what appeared to be an authentic government data request. The fraudulent communication originated from a genuine government agency email domain and successfully cleared standard domain verification protocols.

⚠ ALERT: Revolut falls for a FAKE government request, exposing sensitive personal information of customers in a disturbing data breach.

Revolut disclosed that it complied with a fraudulent government request using a spoofed official email and valid credentials, exposing PII… pic.twitter.com/3RPO6OYs1N

— Coin Bureau (@coinbureau) September 12, 2026

According to Revolut, the organization processed the request based on its seemingly legitimate characteristics. The firm has declined to specify which government agency’s domain was exploited or provide details regarding how unauthorized individuals obtained access to official channels.

Scope of Compromised Information

The data breach encompassed extensive personal and financial details. Customer information including complete legal names, birth dates, professional occupations, residential addresses, email contacts, and telephone numbers were compromised.

Official identification materials including passport copies and driving licenses formed part of the disclosure, alongside verification selfies customers provided during account setup procedures. The company emphasized that biometric facial recognition data remained secure.

Banking records represented a substantial portion of the exposed material. The unauthorized recipient obtained account statements, International Bank Account Numbers (IBANs), account creation dates, withdrawal logs, and comprehensive transaction ledgers.

Cryptocurrency-related information featured prominently in the leaked statements. Bitcoin wallet reference codes were visible within account documentation. Complete Bitcoin transaction logs were also transmitted, creating privacy concerns for cryptocurrency holders whose financial movements can now be traced to their real-world identities.

The company confirmed that cryptographic private keys, login credentials, and complete payment card numbers remained protected and were not included in the unauthorized disclosure.

Impacted User Base

Blockchain investigator ZachXBT published the customer notification via Telegram on September 11. His assessment suggests the incident maintained a relatively narrow scope and may have specifically targeted wealthy account holders. Revolut has not disclosed precise figures regarding affected customer accounts.

The platform’s global customer base exceeds 80 million users. This figure represents total registered accounts across all markets, not the subset impacted by this security incident.

The customer advisory does not clarify whether all compromised accounts contained identical data categories or explain the selection criteria for targeted individuals.

Compliance and Security Implications

According to the UK Information Commissioner’s Office, data security failures can facilitate identity theft, fraudulent activities, and monetary damages. Regulatory frameworks mandate that organizations report qualifying breaches within 72 hours and inform affected individuals without unreasonable delay.

The notification image distributed by ZachXBT does not indicate whether Revolut has filed mandatory regulatory reports or specify when the company discovered the fraudulent nature of the request.

Beyond the customer notification, Revolut has maintained public silence regarding the incident. The organization has not disclosed which government entity’s email infrastructure was compromised.

This security breach occurs amid Revolut’s business expansion initiatives. The company secured provisional approval for a United States banking charter from the Office of the Comptroller of the Currency on September 3. Additionally, Revolut introduced its euro-denominated stablecoin, EURR, to select European customers during August.

These business developments remain unconnected to the data disclosure incident. Revolut has not indicated that any affected individuals maintain US-based accounts.

The post Revolut Falls Victim to Spoofed Government Email, Bitcoin Data Compromised appeared first on Blockonomi.

Read Entire Article