Privacy News Revolut reportedly disclosed customer data, including Bitcoin records, after unauthorized government request

enaph

Level 30
Thread author
Verified
Honorary Member
Top Poster
Well-known
Forum Veteran
Jun 14, 2011
1,850
2
12,417
2,879
Null Island
A number of Revolut customers reported being told that some of their personal and financial data, including Bitcoin transactions, was disclosed in response to a government request believed to be legitimate.

According to an email text shared by onchain sleuth ZachXBT, the request was sent from an unauthorized email account using the government agency's official domain and carried valid domain authentication credentials.

The exposed data included customers' full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers. Identity and verification information, including passport or driver's license copies and verification selfies, was also listed.

The exposed financial data included account statements, IBANs, withdrawal records and full transaction histories, including Bitcoin activity. The email said biometric facial telemetry data was not shared.

Experts suggested that Revolut may have failed to recognize that the request was fraudulent before sharing customer information.

"While the incident is likely limited in size it seems to have been targeted at high net worth users," ZachXBT said.

Revolut has yet to comment on the reported data exposure.
 
Who's going to pay for the damages of this breach?
People could get kidnapped (like those big fishes in France that gold sold by the national tax system corrupted officials), extorted or have their identity stolen.

Revolut better tackle this as best as possible and avoid this from happening again.
 


Hi, this is a potentially serious targeted disclosure incident, but at present the thread contains a secondary report and a quoted notification—not an official Revolut confirmation. The safest conclusion is that the report is credible enough for possibly affected customers to act on, while the incident’s scope and exact cause remain unverified.

What the report would mean​

If the quoted notification is authentic, this appears less like Revolut’s systems being directly breached and more like its lawful-request process being deceived through a compromised or unauthorized government-domain account. Valid domain authentication can show that an email was authorized by that domain’s infrastructure; it does not prove that the sender had legitimate authority to request records. That distinction is rather important—email authentication is not a warrant.

The reported combination of identity documents, contact details, account history and Bitcoin transactions would be highly useful for targeted phishing, impersonation, account-recovery fraud, SIM swapping attempts and physical extortion. It would not, by itself, expose a Bitcoin wallet’s private keys or let somebody spend its funds.

What potentially affected customers should do​

Anyone who received a disclosure notice should:

  1. Verify the notice through the Revolut app or an independently obtained support channel. Do not use links or telephone numbers in the email.
  2. Secure the associated email account and mobile number: use unique passwords, enable strong MFA where available, review active sessions and recovery details, and add a carrier account PIN or port-out protection.
  3. Review Revolut sessions, connected devices, beneficiaries and recent activity. Report anything unfamiliar through the app.
  4. Treat detailed calls and messages as hostile by default. A scammer may quote real transactions, addresses or identity details to sound convincing. Revolut, police and government agencies do not need a seed phrase, one-time code or remote access to a device.
  5. Consider the physical-risk angle if the disclosed history reveals substantial cryptocurrency holdings. Avoid discussing holdings publicly and review whether reused postal addresses or telephone numbers expose family members.
  6. Preserve the notification and relevant correspondence. It may be needed for a complaint to Revolut or the appropriate data-protection authority.

Rotating Bitcoin addresses cannot erase an already disclosed transaction history. Moving funds is warranted if wallet secrets may separately have been exposed—not merely because transaction records were disclosed.

What still needs confirmation​

The decisive missing item is an official statement from Revolut establishing whether disclosure occurred, how many customers were affected, which data fields were actually supplied, which jurisdiction was involved and what safeguards have since changed. The shared wording should therefore not yet be treated as proof that every listed category was exposed for every recipient.

Customers who received no notice do not need to assume their records were included, although normal vigilance against tailored phishing is sensible. The interesting security question is not merely whether the sending domain passed authentication, but whether Revolut independently verified the requesting officer, legal authority, case reference and approved delivery channel before releasing data.
 
Update:
According to emails sent to impacted users and a statement from a company spokesperson, attackers managed to send a data request from an unauthorized account hosted on an official government domain. Because the email passed standard authentication checks, Revolut treated it as legitimate and handed over the requested information before realizing it was fraudulent.
Revolut blocked the sender address, notified the relevant government agency, police, and regulators, and reached out to the small group of affected (potentially just high-net-worth) users. The company emphasized that internal systems were not breached and customer funds remain completely safe.