Revolut disclosed sensitive customer data—including passport copies, verification selfies and full Bitcoin transaction histories—after fulfilling a fraudulent request sent from a government agency’s legitimate email domain.
A Revolut spokesperson confirmed it was “a sophisticated external impersonation scam,” said a “limited” number of customers were affected, and stated systems and funds were unaffected, but declined to give numbers or name the agency.
ZachXBT said the breach appeared to target high-net-worth users, raising “wrench attack” concerns amid a wave of similar leaks.
Fintech giant Revolut handed sensitive customer data, including passport copies and full Bitcoin transaction histories, to a malicious actor after falling for a fraudulent request disguised as a legitimate government inquiry.
According to a customer notification circulated by crypto investigator ZachXBT, Revolut received a request for customer information that appeared to come from a government agency, sent from an unauthorized email account using the agency’s official domain.
Myriad: Bitcoin’s next move? Click to make your prediction.
Because the message carried valid domain authentication credentials, Revolut fulfilled it in the belief it was genuine.
The exposed data was extensive. Per the notice, it spanned identity details such as full name, date of birth and occupation; contact information including postal address, email and phone number; and document and verification data, including a copy of the victim’s passport or driver’s license and the selfie provided for verification.
Most alarming for crypto holders, the financial data included account statements with IBAN and wallet reference numbers, withdrawal records and full transaction history, including Bitcoin. Revolut said no biometric facial telemetry data was involved.
A Revolut spokesperson confirmed the breach to TechCrunch, describing it as “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
The company said a “limited” number of customers were affected, that it had blocked the email address and alerted the agency, law enforcement and regulators, and that its systems and customer funds were unaffected. Revolut declined to say how many people were hit or which agency was impersonated.
ZachXBT said the incident appeared to target high-net-worth users, a concern given the surge in violent “wrench attacks” against known crypto holders. The leak drew sharp criticism, with several users on social media arguing the episode shows know-your-customer rules have created risk without meaningful benefit.
The breach lands amid a rough stretch for firms holding crypto users’ personal data. Hardware wallet maker Trezor recently saw a support-vendor breach widen to expose tens of thousands more customers, while X appeared to suffer a data breach of its own that flooded users with password resets.
Revolut, which launched its euro-pegged EURR stablecoin this year, is currently weighing an IPO.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.