Revolut confirmed to TechCrunch on 12 September that it had disclosed sensitive customer data to an unauthorised third party after receiving fraudulent information requests sent from what the company described as a legitimate government agency’s own email domain. The exposed data included names, dates of birth, addresses, passports and driving licences, verification selfies, IBANs, account opening dates, and full transaction histories, including Bitcoin withdrawal records and wallet reference numbers.
Revolut called the episode a sophisticated external impersonation scam rather than a breach of its own infrastructure, since the fraudulent requests passed the domain authentication checks the company uses to verify genuine law enforcement inquiries. Researchers who reviewed the leaked material said the targeting looked deliberate, focused on high net worth customers whose crypto holdings could now be tied to their real identities.
A company spokesperson said only that a limited number of customers were affected and that each had been contacted directly, declining to give a number. That has not stopped the people holding the data, who began publishing customer documents on Telegram this week and said they would keep releasing more, daily, until Revolut pays to make it stop.
Revolut says no accounts, funds or private keys were touched, which is true as far as it goes, but identity documents matched to Bitcoin transaction histories are exactly the material used for targeted phishing and extortion rather than direct theft. Which government agency’s domain was spoofed, how many customers are actually affected, and whether Revolut intends to pay anything, are all questions its statement left open.



