Breaches

Revolut gave away customers' data

Revolut gave away customers' data

Revolut disclosed customer passports and Bitcoin histories after a fake government request

The email came from a real government domain and passed authentication checks. Revolut concluded afterwards that it was not genuine.

Revolut handed over customers' passport copies, verification selfies and full transaction histories to someone posing as a government agency, according to security notices sent to affected customers on Friday.

The request that triggered the disclosure was sent from an unauthorised account on a genuine government domain, not from a lookalike address, and carried valid domain authentication credentials. Revolut fulfilled it in the belief that it was an authentic request from the agency. The company later concluded it was not.

The notice lists what may have been included: full name, date of birth and occupation; postal address, email address and phone number; a copy of a passport or driving licence and a facial verification selfie; and account statements covering IBAN, account status, opening date and wallet reference number, along with withdrawal records and complete transaction history including Bitcoin. The notice says biometric facial telemetry data was not shared.

This is not a reported intrusion into Revolut's systems. Login credentials, card numbers, private keys and funds are not among the data described, and the company told customers that accounts, funds and assets remain secure.

Revolut says it contacted the agency to validate the request, alerted it to the unauthorised mailbox on its domain, blocked the address internally, began notifying regulators and applied precautionary protections to affected accounts.

Several important things remain unpublished. Revolut has not named the agency, said how someone obtained a mailbox on its domain, given a number of affected customers, said when the request arrived or was fulfilled, or indicated whether the disclosed files have been used. No regulator has commented publicly.

On-chain investigator ZachXBT, who circulated the customer notices, believes the incident was limited in size and appears to have been aimed at high-net-worth users. Revolut's notice does not confirm the size of the affected group or how those customers were selected.

Marc Zeller, one of the customers who published his notice, argued that identity verification requirements leave banks holding large files of identity documents and transaction records that become a liability the moment a request is answered in error. He said Revolut had recently asked him for further data under threat of account closure within 20 days.

The incident is separate from a July claim on a cybercrime forum offering 75 million Revolut records. Revolut said at the time that it found no indication of a breach and that sample identifiers did not match valid accounts.

Revolut has not issued a public statement on the disclosure. The account above comes from customer notices shared by recipients and reported by crypto.news.



International Cyber Digest

Get the ICD Newsletter

Subscribe for source-forward cyber news, OSINT notes, breach updates, and analysis. Have evidence or a lead? Send it to ICD.

Subscribe Send a tip