On-chain investigator ZachXBT revealed that Revolut recently sent notifications to some customers, stating that the company mistakenly treated a forged government information request as an official law enforcement or regulatory document, and subsequently provided sensitive user data to unauthorized parties. The information that has been made public indicates that this incident is more of a case of accidental disclosure rather than a traditional system intrusion or theft of funds.
Leaked information includes identity documents and Bitcoin transaction records.
According to the customer notification shared by ZachXBT on Telegram, the leaked information includes names, dates of birth, occupations, addresses, email addresses, phone numbers, as well as copies of identification documents such as passports or driver's licenses, and selfie photos submitted during account verification.
In terms of financial information, the disclosed content also includes IBAN, account status, account opening date, Bitcoin wallet reference number, withdrawal records, as well as a complete transaction history, which includes Bitcoin transfer records. Revolut indicates that facial biometric telemetry data was not within the scope of this leak, but verified selfie photos were included.
The company stated that it mistakenly believed the request came from an official domain name.

Revolut stated in the notification that the relevant emails came from an unauthorized account, but used the real official email domain name of a government agency and passed the domain name authentication check. Therefore, the company provided the information on the basis of 'reasonable belief that the request was genuine and valid'.
This means that the incident was not a direct hack into the Revolut system, and there is no evidence to suggest that customer funds were directly transferred as a result. The problem arose when the company mistook a seemingly legitimate external request for a legal instruction and disclosed user data accordingly.
The impact may be limited, but the risk is not low.
ZachXBT indicates that the number of affected accounts appears limited at present, but attackers may be specifically targeting high-net-worth clients. Some users received an official alert email from Revolut on September 11.
Although there is currently no public figure for the total number of people affected, the combination of leaked information alone is sufficient to pose a high risk. Once identity documents, bank account information, and complete transaction records fall into the hands of criminals, they could be used for identity theft, targeted phishing, or more precise social engineering attacks surrounding holdings of crypto assets.
Additional information:Before the incident occurred, Revolut was still pursuing expansion in encryption and banking services. Reports indicate that by the end of August, the company had launched the euro-stablecoin EURR to some customers in Denmark, Poland, and Portugal, and on September 3rd, it received conditional approval from the US Federal Reserve (FRB) for its proposed banking operations in the United States.










