Revolut disclosed customer identity and financial records to an unauthorized party after accepting a fraudulent request that appeared to come from a government agency, according to a customer notice circulated on Sept. 11.
The incident affected a subset of customers. The disclosed information reportedly included passport or driver’s license copies, facial verification images, contact details and Bitcoin transaction histories.
A key concern is how the request passed Revolut’s verification process. The mailbox reportedly operated inside an official government domain and carried valid SPF, DKIM and DMARC authentication. Those signals made the request appear legitimate to the company.
Revolut later contacted the government agency to verify the request. That process reportedly revealed that an unauthorized account had been created within the agency’s domain infrastructure.
How the Data Was Exposed
The customer notice identified several categories of potentially exposed information:
- Names, dates of birth and occupations
- Postal addresses, email addresses and phone numbers
- Passport or driver’s license copies
- Facial verification images
- Account statements and wallet reference numbers
- Withdrawal records and Bitcoin transaction histories
The notice reportedly said that biometric facial telemetry was not compromised. It also did not indicate that private keys, passwords, card PINs or customer funds were stolen.
The company reportedly blocked the unauthorized mailbox, notified regulators and introduced additional protective measures for affected customers.
Crypto Privacy Risks
The incident highlights a growing privacy concern for cryptocurrency users. Transaction histories can reveal financial activity even when attackers cannot directly access digital assets.
Revolut’s crypto service uses custodians to protect private keys, while customer crypto exposure remains recorded on the company’s internal ledger. Therefore, disclosure of transaction records does not necessarily provide direct control over customer assets.
The exact number of affected customers remains unclear. Revolut also has not publicly identified the government agency involved or disclosed whether the same fraudulent mailbox targeted other financial institutions.
The incident underscores the difficulty of defending against sophisticated social engineering. A fraudulent request can appear technically authentic even when the underlying sender is unauthorized.