Revolut recently notified some customers that the company had previously disclosed customer identity information, account details, and transaction records, including Bitcoin transaction history, to unauthorized senders in response to what appeared to be a formal request from a government agency. The disclosed information does not indicate any intrusion into the company's systems, nor is there evidence that customer funds have been transferred away.
Forged requests are sent using official domain names.

According to customer notification, this email did not impersonate a similar address; rather, it was sent directly from the official email domain of a government agency and contained valid domain authentication information. Revolut stated that it was precisely because the email matched the formal characteristics of an official correspondence that the company provided the requested information, based on a "reasonable belief that the request was genuine."
The notification does not specify the name of the institution involved, nor does it disclose how the unauthorized sender obtained the usage rights for the account under that email domain name. The time of the request issuance, the time of information disclosure, and the scope of impact of the incident have also not been made public to date.
ZachXBT indicates that the scale of the incident seems limited, and it may be targeted at high-net-worth users. However, this claim has not yet been confirmed by the Revolut official announcement materials, and the total number of affected customers has not been disclosed either.
Disclosed information includes identity details and transaction records.
The scope of information listed in Revolut includes:
- Customer name, date of birth, and occupation
- Mailing address, email address, and phone number
- A copy of your passport or driver's license, as well as a selfie for identity verification
In addition to identity information, the disclosed content also includes account statements, IBAN, account status, account opening date, as well as reference numbers related to Bitcoin wallets. The notice also mentions that withdrawal records and a complete transaction history are also provided, which include Bitcoin transaction records.
Revolut It should be specifically noted that this incident does not involve remote sensing data from facial biometrics. The existing materials also do not indicate that private keys, account passwords, or complete bank card information have been leaked together. However, for encrypted users, the disclosure of Bitcoin transaction records alongside real-name identity information means that individual financial activities may be more fully correlated with specific identities.
Affected customers are at risk of identity theft.
The common risks of personal data breaches, as identified by the UK Information Commissioner's Office, include identity theft, fraud, and financial loss. However, in the case of this incident, the available public information does not indicate that the relevant data has been further misused.
If the identification documents, contact information, and transaction records of the same customer are disclosed simultaneously, the recipient could theoretically construct a more complete personal financial profile. This is especially true when account transaction details are presented alongside Bitcoin transaction records, as such information is particularly sensitive for holders of crypto assets.
British regulatory guidelines require that institutions report certain personal data breaches within 72 hours if possible after becoming aware of them, and notify the affected individuals as soon as possible in high-risk situations. However, the existing screenshots do not indicate whether Revolut has reported to the regulatory authorities, nor do they disclose when the company first became aware of this unauthorized request.
At the time of the incident, Revolut was expanding its encryption business.
At the time of this incident, Revolut was still pursuing the expansion of its banking and digital asset business. In August, the company announced the launch of the euro-stablecoin EURR for certain customers in Denmark, Poland, and Portugal, with plans to further expand its coverage in Europe thereafter.
In addition, Revolut also received conditional approval from the Federal Reserve Board of Governors earlier this month to prepare for the establishment of a bank in the United States. As previously disclosed, the project still requires deposit insurance, approval from the Federal Reserve, and final regulatory clearance before it can commence operations.
Additional information:Currently, there is no information indicating that this data breach is directly related to the issuance of their stablecoin or the application submitted by the American bank. Revolut stated in August that the company's global customer base had exceeded 80 million, but this number does not represent the actual number of people affected by this incident.











