Key points

  • Revolut confirmed that an unauthorized party sent fraudulent requests from a legitimate government-agency email domain.
  • Notices reviewed by CoinDesk described exposed identity documents, contact details, account records and Bitcoin transaction histories.
  • Revolut says its systems and customer funds were unaffected, but it has not disclosed how many people were involved.

A trusted channel carried a fraudulent request

Revolut has confirmed that sensitive customer information was disclosed to an unauthorized third party after fraudulent requests arrived from a legitimate government-agency email domain. The incident did not begin with a reported break-in to Revolut’s systems; it involved a deceptive request that passed checks used to handle official demands for customer information.

A Revolut spokesperson told Reuters that the company blocked the address after detecting the problem and alerted the relevant government agency, law-enforcement bodies, data-protection authorities and financial regulators. Revolut said its systems and customer funds were unaffected. It did not identify the agency whose domain was used or disclose the number of customers involved.

Related reporting: Blockstream refuses ransom for 598.5 BTC after Liquid exploit

Identity files and Bitcoin activity were included

The categories of information went beyond basic contact details, according to notices sent to affected users and reviewed by CoinDesk. Those notices listed passports or driving licences, verification selfies, names, dates of birth, occupations, home and email addresses, phone numbers, IBANs, account statements, withdrawal records and transaction histories, including Bitcoin activity.

Those details are based on customer notices reported by CoinDesk, while Reuters independently confirmed birth dates, postal and email addresses, phone numbers and identity-document copies. Neither outlet reported that passwords or private crypto keys were among the disclosed data, and Revolut said customer funds were unaffected. Revolut also has not said publicly whether the disclosed information has been misused.

Why the Bitcoin records raise a distinct risk

Bitcoin’s ledger is public, but wallet activity is normally separated from a person’s passport, home address and other identity records. A financial intermediary can hold information connecting those two layers. If such records are exposed together, they may help an attacker identify a customer’s activity, construct convincing phishing messages or target people believed to hold substantial assets.

That is a risk assessment, not evidence that affected Revolut customers have suffered theft. The company’s statement that funds were unaffected is important, but it does not eliminate potential identity theft, impersonation or follow-on social-engineering attempts. The unknown number of affected customers also prevents a reliable assessment of the incident’s scale.

What customers should watch

Affected users should rely on communications inside the Revolut app and be cautious with unexpected calls, emails or messages referring to the incident. Revolut’s U.S. support page says customers can report suspicious activity through secure in-app chat and states that it will not call about a personal account without first sending an in-app alert.

Customers should review recent account activity, reject requests for passwords or verification codes, and contact Revolut directly if a message appears suspicious. These are precautionary steps rather than confirmation that an account has been compromised. Revolut says customers who believe they are facing a scam should stop communicating with the suspected scammer, contact relevant financial institutions and report the matter to police.

Important questions remain unanswered

The central control failure appears to have been authentication of an official-looking request, not protection of the account balances themselves. The next facts to watch are how the legitimate agency domain was used, which request-verification controls failed, how many customers were affected and whether regulators require additional safeguards. Until Revolut or an authority provides those details, claims about the attacker, motive or total impact remain unverified.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.