Revolut Suffers Sophisticated Data Breach via Impersonated Government Request, Exposing Crypto and Personal Data
Fintech giant Revolut has disclosed a rare and concerning security incident involving the impersonation of a legitimate data request process. The company recently notified a subset of its customers that an official-looking data retrieval request, seemingly from a government agency, was in fact from an unauthorized third party. Mistaking the request as genuine, Revolut proceeded to hand over sensitive customer information, including identity details, account records, and complete transaction histories – notably, encompassing Bitcoin transactions.
This incident has garnered significant attention within the cryptocurrency community, not because hackers breached Revolut’s systems, but due to the attackers’ apparent compromise of an email account within a legitimate government agency’s domain. This allowed the fraudulent request to pass standard email authentication checks like SPF, DKIM, and DMARC, effectively bypassing the financial institution’s existing trust mechanisms.
Beyond Passwords: Passports, Selfies, and Bitcoin Records Potentially Exposed
According to the notifications sent by Revolut to affected customers, the scope of the exposed data far exceeds a typical username and password leak. The compromised information includes a comprehensive array of personal and financial details:
- Identity Information: Name, date of birth, and occupation.
- Contact Details: Residential address, email address, and phone number.
- Verification Documents: Copies of identity documents such as passports and driver’s licenses, as well as facial verification photos submitted during account opening. Revolut emphasized that the exposed data consists of the images themselves, not derived biometric telemetry data.
- Financial Records: IBANs, account status, account opening dates, wallet reference numbers, withdrawal records, and a complete transaction history, explicitly including Bitcoin transaction records.
Revolut’s own privacy policy highlights its routine retention of government-issued identification documents, facial data (photos or videos), external crypto wallet information, and customer transaction records to fulfill KYC (Know Your Customer), AML (Anti-Money Laundering), and fraud prevention obligations. The true risk of this incident is not merely that personal data was viewed, but that an unauthorized party may have simultaneously acquired a customer’s real identity, address, financial accounts, and cryptocurrency activity trails.
The Critical Flaw: Not a Revolut Hack, But a Compromised Government Email
Based on currently available information, this incident diverges significantly from traditional database breaches. Revolut stated that the fraudulent request originated from an unauthorized account established within a genuine government agency’s domain infrastructure, complete with valid domain validation certificates. This led the company to “reasonably believe” it was a legitimate government data request. It was only after Revolut proactively contacted the relevant agency for verification that the email account was confirmed as unauthorized.
Following the discovery, Revolut promptly blocked the sender’s address, notified relevant regulatory authorities, and implemented additional preventative security measures for affected accounts. As of September 12th, there have been no public indications that Revolut’s core systems were breached, nor any evidence of customer passwords, payment card PINs, or cryptocurrency private keys being stolen. Furthermore, no public reports have emerged of customers’ funds being directly transferred as a result of this incident.
The incident primarily exposes a vulnerability in how financial institutions handle law enforcement and government data requests: an over-reliance on email domain identity verification can still be circumvented by sophisticated social engineering tactics.
Bitcoin Transaction History Exposure: A Higher Stakes Risk
Perhaps the most critical aspect for the cryptocurrency market is the simultaneous disclosure of Bitcoin transaction history alongside real-world KYC data. While on-chain addresses are typically pseudonymous, allowing external observers to see transactions without knowing the true holder, this breach changes the game. Once an attacker possesses a customer’s passport name, residential address, phone number, email, Revolut wallet reference, and BTC transaction records, they can potentially cross-reference on-chain activity with real-world identities.
It’s crucial to note that this does not equate to private keys being stolen, meaning funds cannot be directly transferred using this data alone. However, it significantly elevates the risk of subsequent targeted phishing attacks, SIM swap fraud, account recovery scams, impersonation attempts, and even blackmail, particularly targeting high-net-worth individuals.
On-chain researcher ZachXBT suggested that the scale of the incident might be limited, potentially focusing on high-net-worth clients. However, Revolut has not officially disclosed the exact number of affected customers, so the “wealthy client focus” remains a researcher’s assessment, not an official Revolut conclusion.
As of September 12th, Revolut has not yet announced how many customers were affected, nor has it publicly named the government agency whose domain was impersonated. Other unconfirmed details include the actual date of data delivery, whether attackers issued similar requests to other banks or exchanges, and if the stolen data has been further sold, used for fraud, or employed for on-chain tracking.
Revolut’s Massive Growth Amplifies Security Incident Impact
The timing of this incident is particularly sensitive, as Revolut has evolved from a fintech startup into a major global financial platform. Recent data indicates Revolut serves over 80 million retail customers worldwide, adding approximately one million new customers every 17 days, with a goal to exceed 100 million users by mid-2027.
By the end of 2025, Revolut’s retail customer base reached 68.3 million, a 30% year-on-year increase, alongside 767,000 business clients. Its 2025 revenue surged by 46% year-on-year to £4.5 billion (approximately $6 billion USD), with pre-tax profits growing 57% to £1.7 billion (approximately $2.3 billion USD). Total customer asset balances also saw a substantial 66% increase, reaching £50.2 billion (approximately $67.5 billion USD).
Just this month, the U.S. Office of the Comptroller of the Currency (OCC) granted conditional approval for Revolut’s national bank charter application in the U.S. Reuters reported that the company, with its approximately 80 million global customers, plans to officially launch U.S. banking operations as early as the first half of 2027, offering services including checking accounts, credit cards, foreign exchange, cryptocurrency, and stablecoin-related offerings. Consequently, any vulnerability involving KYC or cryptocurrency transaction data processing carries significantly higher regulatory and reputational risks than for a typical fintech company.
“Legitimate Government Requests” Emerge as a New Financial Security Attack Surface
The core issue revealed by the Revolut incident is that even without a traditional hacking breach, financial institutions can still hand over highly sensitive data due to the “hijacking of a trusted source.” Government and law enforcement agencies are legally empowered to request customer KYC, account, or transaction records from banks as part of financial crime investigations; Revolut’s own privacy policy explicitly states it shares customer data with government agencies when legally required.
However, if a financial institution deems a data request trustworthy solely because the sender’s address is within a genuine government domain and the email passes SPF, DKIM, and DMARC checks, attackers who first compromise an email account on the government’s end can leverage this “legitimate identity” to bypass bank defenses.
For high-net-worth customers holding cryptocurrency, this type of attack could be even more dangerous than a typical password leak: passwords can be changed, credit cards can be canceled, but names, passports, facial photos, addresses, and historical on-chain transactions, once linked, are virtually impossible to “reset.”
The Revolut incident is therefore more than just a personal data leak; it underscores that financial institutions, when processing data requests from government and law enforcement agencies, can no longer rely solely on email and domain verification. They must implement independent callbacks, digital signatures, government request portals, or other out-of-band verification mechanisms to confirm that the entity requesting the data is indeed the legitimate government agency.
Disclaimer: This article is for market information purposes only. All content and views are for reference only, do not constitute investment advice, and do not represent the views and positions of the Block Tempo. Investors should make their own decisions and trades. The author and Block Tempo will not bear any responsibility for direct or indirect losses resulting from investor transactions.