Revolut disclosed that it provided highly sensitive personal and financial information to an unauthorized party after receiving what appeared to be a legitimate government request, according to on-chain investigator ZachXBT.
The company sent notification emails to affected customers admitting that the exposed records included passports, verification selfies, addresses, and complete Bitcoin transaction history.
What Was Disclosed
The request originated from an unauthorized email account using a government agency's actual email domain and carried valid domain authentication credentials, Revolut explained. The company fulfilled the request believing it to be legitimate.
Disclosed information potentially included customers' full names, dates of birth, occupations, home addresses, email addresses, and phone numbers. More sensitive material included copies of passports and driver's licenses, as well as selfie images provided during the verification process. Biometric facial telemetry was not compromised, according to the company.
Financial information was also provided, including account statements containing IBANs, account-opening dates, wallet reference numbers, withdrawal records, and full transaction history including Bitcoin transactions.
Revolut has not publicly identified the government agency involved. The notice to customers does not indicate whether passwords, private keys, or customer funds were accessed.
Scope Remains Unclear
ZachXBT described the incident as likely limited in scope, suggesting that perpetrators targeted only high-net-worth users. This assessment has not been independently confirmed or verified by Revolut. The company has not disclosed the number of affected customers.
The incident appears to represent an unauthorized disclosure rather than a direct compromise of Revolut's infrastructure. Revolut instructs government and law-enforcement bodies to submit official information requests through a dedicated channel.


