Revolut, a UK-based neobank serving over 70 million customers globally, inadvertently disclosed customer data to unidentified threat actors who posed as a government agency.
According to notifications sent to customers, Revolut received an information request from an unauthorized email address hosted on a fraudulent domain. The email carried authentic domain authentication credentials, leading Revolut to fulfill the request under the belief it was a legitimate government agency inquiry.
The leaked information included names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Additionally, Revolut shared verification documents containing passport and driver's license images along with facial verification pictures, exposing affected users to identity theft risks.
Revolut did not publicly identify which government agency the fraudulent request impersonated. The company has not disclosed the number of users affected by the breach.
Marc Zeller, founder of the Aave Chan Initiative, confirmed he was among those impacted. Cryptocurrency analyst ZachXBT noted that while the incident appeared limited in scope, the leaked data appeared targeted at high-net-worth users, increasing their exposure to targeted attacks.
The breach has intensified ongoing criticism of mandatory know-your-customer (KYC) requirements in the financial and cryptocurrency sectors, with observers noting that data leaks and physical security threats have increased as institutions collect and store sensitive personal information.


