Smaller Revolut Accounts Also Report Receiving Data Exposure Notices
Revolut’s disclosure of sensitive customer information to an unauthorized third party may not have been limited to high-net-worth customers, according to new community reports that challenge an early theory about how victims were selected.
The British fintech confirmed on Sept. 12 that customer data was disclosed after it received fraudulent information requests sent from an email account operating within the domain of a legitimate government agency.
Revolut said the request appeared authentic because it came through the agency’s real domain infrastructure. The company later determined that the sender was unauthorized, blocked the address and alerted the government agency, law-enforcement authorities, data-protection bodies and financial regulators.
Revolut said its own systems were not compromised and customer funds were unaffected. It has not disclosed how many customers were affected or publicly identified the government agency whose domain was used.
The information potentially disclosed was unusually sensitive.
Customer notifications circulating publicly indicate the material could include names, dates of birth, occupations, postal addresses, email addresses, phone numbers, passport or driver’s licence copies and facial verification photographs.
Financial information potentially shared included account statements containing IBANs, account status and opening dates, withdrawal records, wallet reference numbers and complete transaction histories, including Bitcoin activity.
Revolut distinguished the facial verification photographs from biometric facial telemetry and said the latter was not involved.
The incident initially appeared to have a relatively narrow targeting profile.
On-chain investigator ZachXBT, who helped bring wider attention to the case, said the incident appeared likely to be limited in size and seemed to be targeting high-net-worth users.
That assessment has not been confirmed by Revolut, however, and subsequent reports from Revolut’s online community raise questions about it.
A Sept. 12 Reddit thread discussing the breach was updated after users began reporting that accounts with substantially smaller balances had also received notifications.
One commenter said the affected Revolut account held only €4 and had previously been used for some small crypto payments. Another user said they knew four people in Eastern Europe who received the notice but whom they would not consider high-net-worth individuals.
Those claims are community reports and cannot independently establish the profile of the wider affected group. They do, however, make it harder to assume that account wealth alone determined who was targeted.
Revolut has not explained how the fraudulent requester selected the customers whose records were sought.
That distinction matters because the exposed information potentially connects conventional identity information to cryptocurrency activity.
A passport copy or home address represents one type of privacy risk. A Bitcoin transaction history linked to that same verified identity potentially provides much more context about a customer’s financial activity.
The problem resembles the broader security issue exposed by the recent Brevo breach affecting crypto firms: security controls can fail even when communications originate through infrastructure that appears legitimate.
In Brevo’s case, attackers gained access to legitimate email infrastructure used by crypto companies. In Revolut’s case, the fraudulent correspondence came through a legitimate government-domain environment. Both incidents weaken one of the assumptions users and companies normally make when validating communications — that an authentic domain strongly indicates an authentic sender.
The Revolut disclosure also comes as financial platforms increasingly hold both traditional banking information and detailed digital-asset records. Revolut offers banking, payments, investing and cryptocurrency services under the same broader customer relationship, giving its compliance systems access to data that can span multiple financial activities.
Its own privacy documentation states that it collects identity documents, financial information, facial images and other data as part of Know Your Customer checks, fraud prevention and regulatory compliance.
Similar AML compliance requirements across the crypto sector have made centralized financial platforms substantial repositories of customer identity and transaction information.
Revolut is also preparing for a potential public listing and has been targeting a valuation of as much as $200 billion, according to Reuters, increasing the investor relevance of an incident that touches the company’s compliance and data-governance infrastructure.
The Bigger Risk May Sit Outside Revolut
The most consequential unanswered question is not necessarily how many Revolut customers were affected.
It is whether the fraudulent government mailbox was used anywhere else.
Revolut’s explanation suggests the attacker did not need to penetrate the fintech’s customer database or take over individual accounts. Instead, the attacker appears to have exploited a trusted pathway that financial institutions already use to respond to legitimate government requests.
That creates a potentially broader problem.
Banks, exchanges and payment companies routinely receive lawful demands for customer records. Those workflows are necessary for criminal investigations, sanctions enforcement, fraud investigations and other regulatory processes.
They also create a privileged route to extremely sensitive information.
Centralized crypto exchanges can hold exactly the type of records investigators seek when cryptocurrency reaches an identifiable account: KYC information, login records and transaction histories. The Revolut incident demonstrates why authentication of the requester is therefore just as important as securing the underlying customer database.
If the compromised government-domain account contacted only Revolut, the event may remain a contained fintech security failure.
If the same mailbox sent requests to multiple banks, crypto exchanges or payment companies, the scope becomes substantially different.
There is currently no public evidence establishing that this happened.
But that is precisely why identifying the affected agency matters. Other financial institutions cannot easily audit their own legal-request histories for the same sender if they do not know which authority or mailbox was compromised.
The type of data exposed also raises a different security concern for crypto users.
Recent incidents have shown how stolen customer information can later become useful for highly targeted phishing attacks. The more information an attacker has about a victim’s financial relationships and crypto activity, the easier it becomes to construct convincing impersonation attempts.
That does not mean the Revolut data has been used for phishing, theft or physical targeting. No such outcome has been established.
But identity documents, addresses and detailed Bitcoin histories are difficult data to replace once exposed. A password can be changed. A passport can eventually be replaced. A historical transaction record linking an identity to financial activity cannot simply be reset.
That makes this different from an ordinary account takeover where the immediate objective is normally unauthorized access to funds.
Here, Revolut says customer funds remained safe. The asset lost was information.
For investors, the question is therefore less about direct financial losses and more about controls.
Revolut built a financial platform that depends heavily on digital identity, automated compliance and the ability to exchange sensitive information with regulators and law enforcement. A failure at that interface exposes a weakness in precisely the infrastructure that regulated fintech companies increasingly depend on as they scale.
The new reports from smaller account holders also complicate the early narrative.
If victims were not selected primarily by wealth, investigators will need another explanation for why those particular customer records were requested. Crypto activity, geography, specific transaction patterns or information already held by the attacker are possible theories, but none has been established publicly.
The next meaningful disclosure therefore needs to answer three questions: how many customers were affected, how they were selected and which government-domain account submitted the requests.
Until then, the Revolut incident should not be viewed simply as a leak targeting wealthy crypto holders.
It may instead be evidence of something more structurally important: a trusted government-to-financial-institution information channel was successfully impersonated, and the public still does not know whether Revolut was the only company that trusted it.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

