started · updated
Revolut disclosed customer data following fake government request
Fintech company Revolut has confirmed that it disclosed sensitive customer information to an unauthorized third party after mistakenly responding to a fraudulent request that appeared to be from a legitimate government agency. The request was sent from an unauthorized account using an official government email domain and carried valid domain authentication credentials, leading staff to believe the request was authentic.
The disclosed data includes highly sensitive personal and financial records, such as full names, dates of birth, home addresses, email addresses, and phone numbers. More critical information includes copies of passports or driver’s licenses, verification selfies, account statements with IBANs, and complete transaction histories, including Bitcoin activity.
On-chain investigator ZachXBT noted that the incident may have specifically targeted high-net-worth individuals. While the disclosure links real-world identities to Bitcoin transaction histories, Revolut stated that biometric facial telemetry, passwords, private keys, and customer funds were not compromised. The company has notified regulators and the relevant authorities and has blocked the fraudulent sender.