- Several Revolut customers reportedly received notices saying personal and financial information was disclosed in response to what was believed to be a legitimate government request.
- The exposed information reportedly included identity documents, verification selfies, contact details, account statements and complete transaction histories, including Bitcoin activity.
- The request allegedly came from an unauthorized email account using the government agency’s official domain and valid domain authentication credentials.
Revolut reportedly disclosed sensitive customer information after responding to a government data request that was initially believed to be legitimate.
According to the text of an email shared by onchain investigator ZachXBT, several Revolut customers were informed that some of their personal and financial information had been provided in response to the request.

The request reportedly originated from an unauthorized email account operating through the government agency’s official domain and carried valid domain authentication credentials, making it appear legitimate.
The incident raises concerns about phishing and identity theft risks for affected customers given the amount of information reportedly disclosed.
Identity Documents and Selfies Were Reportedly Exposed
The personal information involved reportedly included customers’ full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers.
More sensitive identity verification information was also listed.
This reportedly included copies of passports or driver’s licenses along with selfies customers had submitted during identity verification procedures.
However, the email stated that biometric facial telemetry data was not disclosed.

Bitcoin Transaction Histories Were Included
The reported exposure also extended beyond personal identification information.
Financial data provided in response to the request reportedly included account statements, IBANs, withdrawal records and full transaction histories.
Those transaction records included customers’ Bitcoin activity.
The combination of financial histories, identity documents and contact information could make affected customers more attractive targets for highly personalized phishing or impersonation attempts.
Fraudulent Request Raises Security Questions
Experts suggested Revolut may not have recognized that the government request was unauthorized before providing the information.
The use of an official government domain and valid authentication credentials could have made the request significantly harder to identify as fraudulent.
Based on the information shared, the incident involved the disclosure of customer information rather than the direct theft of funds.
However, customers whose information was affected could face increased risks from phishing, impersonation and other targeted attacks using the exposed data.
Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.

5 hours ago
26









English (US) ·