The incident is particularly concerning because the information potentially disclosed goes well beyond ordinary contact details. Revolut said affected records may include identity documents, verification selfies, account statements, withdrawal records and complete transaction histories, including Bitcoin activity.
How the Fraudulent Request Passed Revolut’s Checks
According to the customer notice, Revolut received what appeared to be a legitimate government information request. The email did not simply spoof the agency’s address. The unauthorised mailbox had been created within the government’s actual email infrastructure and the message carried valid domain authentication credentials.
That distinction matters. Email authentication systems such as SPF, DKIM and DMARC can help determine whether a message is authorised to use a domain, but they do not establish that the individual controlling an authorised mailbox is actually entitled to request customer information.
Revolut said it fulfilled the request under the reasonable belief that it was genuine. The company later contacted the government agency to verify the request and discovered that the mailbox was unauthorised. It then blocked the address, alerted the agency, notified regulators and began contacting affected customers. The incident highlights why trusted identities remain a major target for social engineering attacks.
What Customer Information Was Disclosed?
The customer notification lists several categories of information that may have been included:
- Identity details: full name, date of birth and occupation.
- Contact details: postal address, email address and telephone number.
- Verification data: copies of passports or driving licences and facial verification images.
- Financial data: account statements, IBAN details, withdrawal records and complete transaction histories, including Bitcoin transactions.
Revolut said that biometric facial telemetry was not involved or compromised. The notice also does not indicate that passwords, card PINs or cryptocurrency private keys were disclosed. There is currently no public indication that customer funds were directly stolen as part of the incident.
Why the Bitcoin Data Could Be Especially Valuable
The combination of identity and financial information creates a more serious risk than a conventional customer database leak. A passport copy, residential address, verification selfie and Bitcoin transaction history can give an attacker a detailed profile of a customer’s identity and cryptocurrency activity.
That information could potentially be used for targeted phishing, impersonation, account-recovery attacks or attempts to identify cryptocurrency holdings. Previous crypto security incidents have shown how identity and account information can become useful long after an initial breach.
Revolut Has Not Disclosed the Full Scope
Several important questions remain unanswered. Revolut has not publicly identified the government agency involved, explained how an unauthorised mailbox was created inside its domain, disclosed the number of affected customers or said when the information was actually transferred.
On-chain investigator ZachXBT has suggested that the incident appears limited in size and may have targeted high-net-worth customers. That assessment has not been independently confirmed by Revolut.
Our Take: The most important lesson here is that email authentication is not the same thing as identity verification. A message can legitimately originate from a trusted government domain and still be sent by someone who has no authority to make the request. For financial institutions handling passports, transaction histories and cryptocurrency records, verifying the authority behind a request may be just as important as verifying the email itself.
Follow us on Bluesky, LinkedIn, X, and Telegram to Get Instant Updates


