Revolut disclosed sensitive customer information to an unauthorized third party after receiving a fraudulent data request that appeared to originate from a legitimate government agency.
According to a customer notification shared by crypto investigator ZachXBT, the request came from an unauthorized email account operating through the government agency's official domain. Because the message carried valid domain authentication credentials, Revolut believed the request was legitimate and provided the requested information.
A Revolut spokesperson later confirmed the incident to TechCrunch, describing it as a “sophisticated external impersonation scam” in which an unauthorized party used a legitimate government agency domain to submit fraudulent information requests.
The company said only a “limited” number of customers were affected, although it has not disclosed the exact number or identified the government agency involved.
Passports and Bitcoin Transactions Exposed
The information disclosed was extensive, covering personal identification, contact details, verification documents and financial activity.
According to the customer notice, exposed information could include a person's full name, date of birth, occupation, postal address, email address and telephone number.
More sensitive verification data was also affected, including copies of passports or driver's licenses and selfies submitted during identity verification. Revolut said biometric facial telemetry data was not exposed.
For cryptocurrency users, the compromised financial information was particularly significant. The disclosure reportedly included account statements, IBAN details, wallet reference numbers, withdrawal records and complete transaction histories, including Bitcoin transactions.
Revolut stressed that its internal systems were not compromised and customer funds were not affected.
Revolut Alerts Authorities
After identifying the fraudulent request, Revolut said it blocked the email address involved and contacted the impersonated agency, along with law enforcement authorities and relevant regulators.
The incident differs from a traditional cyberattack because attackers did not need to breach Revolut's infrastructure directly. Instead, they allegedly exploited the credibility of an authenticated government email domain to convince the company to voluntarily disclose customer information.
Revolut has not explained exactly how the attacker obtained access to the government domain or what additional safeguards are being introduced for future information requests.
Crypto Holders Face Additional Security Risks
ZachXBT suggested that the incident may have specifically targeted high-net-worth individuals, although that claim has not been independently confirmed.
Such concerns have become increasingly serious because of the rise in physical attacks against cryptocurrency holders. So-called “wrench attacks” involve criminals using threats, kidnapping or physical violence to force victims to transfer digital assets or reveal wallet credentials.
Information combining a person's identity, physical address and detailed cryptocurrency transaction history could therefore create risks extending beyond conventional financial fraud.
The incident also triggered renewed criticism of know-your-customer requirements, with some crypto users arguing that centralized databases containing identity documents and financial histories can become valuable targets for criminals.
Crypto Companies Face Growing Data Threats
Revolut's disclosure comes amid a broader series of security incidents involving companies holding sensitive cryptocurrency customer information.
Hardware wallet manufacturer Trezor recently warned users about phishing emails following a breach involving a third-party provider, while other incidents have demonstrated how stolen personal information can be used to create increasingly convincing attacks against crypto holders.
The Revolut incident highlights a different vulnerability: even when a company's own infrastructure remains secure, fraudulent government or law-enforcement requests can potentially become another route to sensitive customer data.
The disclosure also arrives during an important period for Revolut. The fintech company launched its EURR euro-backed stablecoin earlier in 2026 as part of a broader push into digital assets and is reportedly considering a future initial public offering.
For affected customers, however, the immediate concern is that highly sensitive information-including identity documents and complete Bitcoin transaction histories-was provided to an unauthorized party despite Revolut's systems themselves remaining uncompromised.



