Revolut disclosed sensitive customer information to an unauthorized third party after fraudulent requests for records were submitted through an email account operating inside a legitimate government agency’s domain, exposing identity documents, account information and potentially full Bitcoin transaction histories.
The fintech said it identified what it described as a sophisticated external impersonation scam and subsequently blocked the email address involved. Revolut said its own systems were not breached and customer funds were unaffected.
The company has not identified the government agency whose domain was used, disclosed how the unauthorized email account was created or said how many customers were affected. It said the incident involved a limited number of users and that affected customers were contacted directly.
According to notifications sent to customers, information potentially disclosed included names, dates of birth, postal addresses, email addresses and telephone numbers. Copies of identity documents, including passports and driver’s licenses, may also have been shared, along with verification selfies.
The financial information involved could be considerably more sensitive. Customer notices indicated that account statements, IBANs, withdrawal records and complete transaction histories may have been provided to the unauthorized party. Those records could include Bitcoin transactions for customers using Revolut’s crypto services.
The distinction between this incident and a conventional cyberattack is important. Revolut says an attacker did not break into its infrastructure and extract a customer database. Instead, the company supplied information after receiving requests that appeared to originate from an authentic government source.
Fraudulent Requests Came Through a Trusted Government Domain
The attack appears to have exploited one of the hardest assumptions for a financial institution to challenge: that a request originating from an authorized government domain is legitimate.
Customer notifications said the unauthorized email account existed within the official agency’s domain infrastructure and carried genuine domain authentication credentials. That made the request appear substantially more credible than a conventional spoofed email sent from a lookalike domain.
Revolut later contacted the government agency to verify the request and discovered that the account was unauthorized. It then blocked the address and notified the government agency, law enforcement, data-protection authorities and financial regulators.
The company has not publicly detailed what verification process was used before customer information was handed over or whether additional controls have since been introduced for government information requests.
Former Mt. Gox CEO Mark Karpelès publicly said he was among the customers who received a notification and shared portions of Revolut’s notice.
Onchain investigator ZachXBT separately suggested the incident may have been focused on high-net-worth customers. That remains speculation rather than a confirmed characteristic of the incident. Revolut has not said affected customers were selected according to wealth, crypto holdings or any other financial profile.
Bitcoin Histories Make the Exposure More Sensitive
The possible disclosure of full transaction histories adds another dimension to the incident because financial records can reveal substantially more than conventional contact information.
A passport or email address creates identity-theft and phishing risks. A detailed financial history can additionally reveal where a person holds money, businesses they interact with, the size and frequency of transfers and potentially their relationship with cryptocurrency wallets.
For customers whose Bitcoin transactions were included, an attacker could potentially combine personal identity data with public blockchain information. That does not give the attacker control over a wallet or access to private keys, but it can make it easier to associate real-world identities with financial activity that would otherwise be more difficult to attribute.
That risk becomes more important as fintech apps increasingly combine traditional bank accounts with crypto services, digital wallets and other financial products in one account.
Revolut itself is moving rapidly in that direction.
Incident Comes as Revolut Expands Deeper Into Banking and Crypto
The disclosure comes at a significant point in Revolut’s expansion.
On Sept. 3, the company received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank. Revolut is still working through remaining Federal Deposit Insurance Corporation, Federal Reserve and OCC approvals, with the proposed U.S. bank targeted for launch in 2027.
The company says it now serves more than 80 million customers globally. Its expansion increasingly blurs the line between fintech, banking and digital assets, similar to the wider move toward regulated banking infrastructure built around blockchain-based money.
Revolut has also begun rolling out its first euro-backed stablecoin. EURR is initially available to selected customers in Denmark, Poland and Portugal, with broader European availability planned.
The token is designed to connect conventional euro balances with blockchain networks and external wallets, extending Revolut’s role beyond payments and foreign exchange into on-chain financial infrastructure.
That strategy reflects an industry-wide shift in which financial apps are trying to become much broader consumer ecosystems. X, for example, has begun embedding banking and payments directly into its platform through X Money, while stablecoin projects are increasingly targeting commercial settlement and cross-border payments.
The Bigger Problem Is Not How the Attacker Got Into Revolut
The uncomfortable part of this incident is that the attacker apparently did not need to get into Revolut at all.
That makes it more interesting than a standard database breach.
Financial companies spend enormous amounts of money protecting login systems, databases, APIs and customer accounts. Those controls matter, but they do not solve the problem exposed here: sometimes the attacker can target the process around the system instead.
If an information request arrives from what appears to be a legitimate government account, the financial institution is placed in a difficult position. Ignore valid government requests and there may be legal consequences. Respond too quickly and an attacker who compromises the requesting authority can effectively turn the institution’s compliance process into a data-extraction tool.
That is a very different threat model.
And the more data a financial super-app collects, the more valuable that threat becomes.
A Fintech Super-App Creates a Richer Data Target
Revolut’s expansion is part of what makes this incident strategically important.
A simple payment app might know someone’s name, card and transaction history. A full financial platform can potentially know their salary, savings, foreign-exchange activity, investments, crypto trades, wallet transfers, identity documents, physical address and spending patterns.
That concentration creates enormous convenience for customers. It also creates an unusually detailed financial profile if information is disclosed improperly.
This is where Revolut’s growth strategy creates a security challenge that becomes larger as the company succeeds.
If Revolut becomes a primary bank for more customers while simultaneously expanding crypto, stablecoins, wealth products and international payments, the value of the information attached to each account rises.
The company therefore needs controls around lawful data requests that are as sophisticated as the controls protecting the account itself.
High-Net-Worth Targeting Would Raise the Stakes
ZachXBT’s suggestion that wealthy users may have been targeted should be treated cautiously until more evidence emerges.
But if that theory proves correct, the risk profile changes.
This would no longer look like an attacker acquiring whatever customer information happened to be available. It could indicate someone already possessed enough intelligence to identify valuable targets and then used official-looking government requests to fill in the missing pieces.
For crypto holders, that combination can be particularly dangerous.
A criminal who knows an individual’s identity, address and Bitcoin transaction history does not necessarily need to compromise their wallet remotely. The information itself can support highly customized phishing, SIM-swap attempts, social engineering or even physical targeting.
That is why transaction privacy matters even when private keys and customer funds remain untouched.
The Next Disclosure Matters More Than the Initial Statement
Revolut has acted by blocking the email address, contacting affected customers and notifying authorities. But several important questions remain unanswered.
The number of affected customers is still unknown. So is the jurisdiction involved, the duration of the fraudulent activity and whether the unauthorized party submitted one request or multiple requests.
It is also unclear what internal verification occurred before Revolut fulfilled the requests and whether another communication channel was used to confirm their authenticity.
Those details will determine how serious the control failure actually was.
If a single highly sophisticated request slipped through before being detected, that is one type of operational failure. If an unauthorized account was repeatedly able to request customer records over a longer period, the implications would be significantly more serious.
The most important lesson is already visible, though.
Financial security is no longer just about stopping someone from breaking through the front door. As fintech platforms become banks, crypto exchanges, payment networks and investment apps at the same time, attackers have more ways to exploit the institutions they trust.
In this case, the weak point appears not to have been Revolut’s customer-facing technology.
It was trust in another institution’s identity.
For a company trying to become one of the world’s largest financial platforms, proving that those trust relationships can be independently verified may now be just as important as proving that its own systems are secure.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

