Article is online

Revolut Shares Sensitive Customer Records After Falling for Fake Government Email

Revolut Shares Sensitive Customer Records After Falling for Fake Government Email

Highlights



Revolut responded to a fraudulent information request that appeared to originate from a government agency, resulting in the disclosure of sensitive customer records. The leaked data reportedly included identity documents, contact details and comprehensive financial records such as IBANs and full Bitcoin transaction histories. A company spokesperson described the incident as a sophisticated external impersonation scam. Revolut says a limited number of customers were affected, systems and funds remain secure, and the company has alerted authorities and blocked the offending email address.


Sentiment Analysis




  • The overall sentiment is mixed-to-negative. The incident raises serious privacy and security concerns for affected customers, especially cryptocurrency holders, who may now be exposed to targeted attacks. The tone of public reaction combines alarm and criticism: users express anger at the breach and frustration that know-your-customer (KYC) processes may increase risk without clear benefit. At the same time, Revolut's assurances that systems and funds were not compromised and that the response involved blocking the address and notifying authorities inject a modestly reassuring note.


    65%





Article Text



Financial app Revolut disclosed sensitive customer information after responding to what it believed was a legitimate request from a government agency. The request reportedly arrived from an email address that used the agency's official domain and carried valid authentication, and the company fulfilled the request before discovering the message was fraudulent. According to investigator reports, the exposed material included customers' identity documents, contact details and extensive financial records.



Details in the notification circulated by a crypto researcher indicate the data set contained full names, birthdates, occupations, postal addresses, email addresses and phone numbers. Document and verification materials reportedly included passport or driver's license copies and the verification selfie supplied during account setup. Financial records were especially extensive and, for cryptocurrency users, included bank account identifiers, wallet references, withdrawal logs and full transaction histories that encompassed Bitcoin activity.



Revolut confirmed the event as "a sophisticated external impersonation scam" and said a limited number of customers were affected. The company stated it blocked the unauthorized email address, alerted the impersonated agency, informed law enforcement and regulators, and that its core systems and customers' funds were not impacted. Revolut has not publicly specified the number of affected customers or identified the agency whose domain was used in the fraudulent request.



Security commentators noted the apparent focus on high-net-worth individuals, a pattern that heightens concerns about targeted physical attacks and harassment, sometimes referred to as "wrench attacks," which have been a part of a wider trend of doxxing and targeted threats against known crypto holders. Critics on social platforms argued the incident underscores a trade-off: while KYC and identity verification are intended to reduce illicit activity, they also aggregate sensitive personal data that can become a liability if mishandled or exposed.



The leak comes at a time when several companies that hold crypto users' personal information have faced breaches. Recent incidents involving support vendors and platform vulnerabilities have exposed thousands of customers, sparking renewed debate over data minimization, vendor security and the responsibility of financial platforms to protect sensitive records. Revolut, which has expanded its services and recently launched a euro-pegged stablecoin, says it is considering its next steps and has taken immediate remedial actions following the incident.



From an operational perspective, the episode highlights the challenges organizations face in validating external requests, even when those requests appear to come from legitimate domains. Implementing multi-factor verification for information requests, strict vendor or agency verification procedures and minimizing the storage of excess personal data are among the measures security experts recommend to reduce future risk. This incident underscores how social-engineering and domain impersonation can defeat standard checks and lead to serious data exposure.



Regulators and law enforcement are reportedly involved, and affected customers have been notified. The full scope and long-term consequences of the disclosure remain unclear until Revolut provides more specifics about the number of accounts involved and the identities targeted. Meanwhile, the episode has prompted renewed scrutiny of how financial platforms balance regulatory compliance requirements with the imperative to protect customer privacy and safety.



Key Insights Table



























Aspect Description
Nature of Incident Revolut fulfilled a fraudulent information request that used a government agency's domain.
Data Exposed Identity documents, contact details, account identifiers, and full Bitcoin transaction histories.
Company Response Blocked the email, notified the agency, alerted law enforcement and regulators; stated limited customer impact and no system or funds compromise.
Risk Implications Heightened risk for targeted attacks on crypto holders and renewed concerns about KYC-related data aggregation.

Last edited at:2026/9/12
#BTC#stablecoin

Power Trader

ZNews Columnist