Revolut

Revolut Confirms Data Breach After Fake Government Request Tricks Verification System

Getting your Trinity Audio player ready...

A convincing scam just exposed a gap in how banks verify government requests — and Revolut customers are now dealing with the fallout.

The fintech company has notified a group of customers that their personal information, including Bitcoin transaction records, ended up in the hands of an unauthorized third party. The cause wasn’t a hack in the traditional sense. According to the customer notice, Revolut received what looked like a legitimate request from a government agency — the message came from a mailbox sitting inside that agency’s actual domain and passed standard email authentication checks. Believing it was genuine, Revolut handed over the data.

What Information Was Exposed

The notice breaks the exposed data into four groups. Identity details cover full names, birth dates, and occupations. Contact information includes home addresses, emails, and phone numbers. Verification records include copies of government IDs and the selfie photos customers submit when opening an account — though Revolut specifies that the biometric data derived from those selfies wasn’t part of what leaked. Financial records round out the list, including IBANs, wallet reference numbers, withdrawal history, and full transaction records, Bitcoin included.

Notably absent: private keys, passwords, card PINs, and account balances. No stolen funds have been reported so far.

How the Story Came to Light

Revolut hasn’t issued a formal public statement through its main account. Instead, the story spread after former Mt. Gox CEO Mark Karpelès posted large portions of the customer notice on September 12, having received it himself the night before. On-chain investigator ZachXBT then flagged the case to his own audience, describing it as likely limited in scope and possibly aimed at high-net-worth accounts. He later said Revolut’s official accounts had blocked him on X, though that detail doesn’t change what’s known about the leaked data itself.

A Different Kind of Risk

What makes this incident notable isn’t the sophistication of a technical exploit — there wasn’t one. It’s that trusted verification systems, like domain authentication, were fooled by a request that looked completely legitimate on paper. Combining a legal name with a passport photo, home address, and full crypto trading history hands attackers everything needed for convincing phishing attempts or social engineering, even without touching a single dollar directly.

Revolut says it has since blocked the fraudulent mailbox, alerted regulators, and applied added protections for affected accounts. Key details remain unclear, including how many customers were affected and which government agency was impersonated.

For now, Revolut is telling customers to treat any unexpected messages referencing the breach as suspicious, and to verify anything through the app rather than email or phone.

Disclaimer: The information in this article is for general purposes only and does not constitute financial advice. The author’s views are personal and may not reflect the views of Chain Affairs. Before making any investment decisions, you should always conduct your own research. Chain Affairs is not responsible for any financial losses.

More From Author

XRPL

XRP Ledger Tops Global Charts With $3.6 Billion in RWA Inflows

ChainAffairs

We deliver the latest cryptocurrency news, analysis, and insights — helping investors stay ahead in the fast-moving digital asset markets.

Quick Links

Your ad here.

Put your brand in front of web3 decisions. Advertise here.
Lets Get Started