Revolut revealed confidential user details to an unauthorized party that sent fraudulent record requests from a valid government agency email domain, the business informed TechCrunch on Saturday.
A Revolut representative characterized the event to The Block as a sophisticated external impersonation scam, mentioning that the company disabled the email address upon discovery. The representative added that Revolut’s platform infrastructure and user funds remained safe and untouched.
Revolut noted that a small group of users suffered impact and that it reached out to them directly, with certain patrons indicating they got emails on Friday. The organization chose not to reveal to The Block the precise number of impacted individuals, whether the breach remained contained to a single region, or the identity of the government agency domain involved.
The shared data potentially encompassed user names, birth dates, physical and electronic mail addresses, phone numbers, and scanned identification records like passports and driver’s licenses, according to a notice dispatched to affected individuals. Verification photographs, bank statements, and historical transaction logs might have also been leaked.
An excerpt of Revolut’s communication to users published openly by former Mt. Gox CEO Mark Karpelès, who mentioned he belonged to the affected group, showed that bank statements, IBANs, cash-out logs, and comprehensive transaction ledgers, such as Bitcoin movements, formed part of the records potentially given to the unverified external entity.
The company also notified the appropriate government office, law enforcement agencies, privacy regulators, and financial authorities, the representative informed The Block.
Blockchain analyst ZachXBT warned his subscribers about the security event, theorizing that the attack might be aimed at wealthy Revolut clients. “While the incident is likely limited in size it seems to have been targeted at high net worth users,” ZachXBT wrote.
Revolut is expanding banking, crypto operations
This event happens while the British financial technology enterprise attempts to grow its banking and digital asset services inside the United States and abroad.
Earlier this month, Revolut secured conditional authorization from the U.S. Office of the Comptroller of the Currency while working to found a federal bank in America, as reported by The Block at that time. The planned financial institution aims to deliver standard banking options together with stablecoin capabilities; Revolut previously detailed those intentions after filing for a de novo banking permit earlier in the year.
Revolut additionally commenced the rollout of EURR, its maiden euro-pegged stablecoin, to chosen clients throughout Denmark, Poland, and Portugal in August. The corporation announced at that period that it catered to 80 million users worldwide and intended to scale the stablecoin across the entire European Economic Area.
The business has likewise been scaling Revolut X, its dedicated cryptocurrency trading venue. In July, Revolut linked the trading platform with third-party artificial intelligence assistants like Claude and Gemini, permitting clients to evaluate markets and execute orders via natural-language commands, as documented by The Block.
Latest in a string of customer-data exposures
The Revolut occurrence represents the newest entry in an ongoing series of consumer data breaches affecting cryptographic and allied fintech entities.
Last month, digital wallet provider SafePal stated that a vulnerability inside an order tracking system leaked names, contact details, delivery addresses, and order specifics belonging to roughly 39,798 users. SafePal emphasized that private keys, recovery seed phrases, and user balances remained secure.
Hardware wallet producer Trezor reported last week that a security lapse at delivery vendor ShipMonk impacted an additional roughly 67,000 U.S. clients, greatly broadening the scale of an event the company initially revealed in August. The exposed records similarly comprised names, electronic mail addresses, phone numbers, delivery addresses, and purchase IDs.
Trezor separately revealed this week that a breach at an external email vendor permitted fraudulent phishing messages to go out utilizing its official domain, an event sharing certain similarities with the Revolut situation wherein bad actors successfully exploited a trusted domain name.
Originally published at https://www.theblock.co/news/business/2026-09-12-revolut-says-customer-kyc-bitcoin-transaction-data-exposed-after-fake-request-from-govt-domain-414516.