mt logoMyToken
ETH Gas
EN

Revolut Confirms Customer Data Breach Through Fake Government Request

Revolut64624

Revolut confirmed on September 12 that an unauthorized third party used a legitimate government agency’s email domain to submit fraudulent requests for customer information, exposing identity documents and Bitcoin transaction activity in the process, according to TechCrunch . The London-based fintech said a “limited” number of its more than 80 million customers were affected by what it described as a sophisticated external impersonation scam.

What the Breach Exposed

According to a notification emailed to affected customers and reviewed by TechCrunch, the exposed data included identity and contact details such as birth dates, postal and email addresses, and phone numbers, as well as copies of identity documents including passports and driver’s licenses. The information may have also included verification selfies, account statements, and transaction data. On-chain investigator ZachXBT, who posted about the incident late on Friday, said the exposure appeared to have been targeted at high net worth users, with Bitcoin activity among the records tied to real-world identities and home addresses.

Revolut’s Response

A Revolut spokesperson told TechCrunch: “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” The company said it blocked the email address after discovering the scam and alerted the relevant government agency, law enforcement, and regulators, adding that “Revolut systems and customer funds are unaffected.” Revolut did not disclose the exact number of impacted individuals, whether the incident was limited to a specific market, or which government agency was involved.

Why It Matters for Crypto Users

The incident shows how social engineering—rather than a technical exploit—can deanonymize Bitcoin holders at a mainstream financial platform. Revolut has expanded its crypto footprint across the EU and beyond, recently moving to delist USDT ahead of the EU’s MiCA deadline . The breach also echoes a broader pattern of security incidents affecting crypto-adjacent services, including the LayerZero executor wallet breach that drained $2.4 million earlier this year.

What Comes Next

The fintech has not set out a timeline for further disclosure, and the full scope of the exposure remains unclear. For affected users, the practical risk is heightened exposure to phishing and identity fraud, since the leaked records pair personal documents with transaction history. Revolut said it contacted affected customers directly, while the incident remains under review by the authorities it notified.

Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup