Revolut Data Breach: Fraudulent Government Email Leads to Bitcoin Record Leak
Key Highlights
- A fraudulent email masquerading as an official government agency request tricked Revolut into disclosing sensitive customer information, including Bitcoin transaction records
- The malicious request originated from a legitimate government agency email domain and successfully cleared authentication protocols
- Compromised information encompasses identity documents, passport scans, selfie verifications, complete names, birth dates, and financial statements
- Bitcoin wallet identifiers and comprehensive transaction logs were among the leaked materials
- Blockchain detective ZachXBT indicated the breach appears contained in scope and potentially focused on wealthy account holders
The fintech platform Revolut inadvertently released confidential customer information to fraudulent actors following receipt of what appeared to be an authentic governmental data request. The perpetrators successfully impersonated an official government entity by utilizing its legitimate email infrastructure, which subsequently cleared domain verification protocols.
According to Revolut’s statement, the company processed the data request under the belief it originated from legitimate authorities. The platform has declined to identify which specific agency’s domain was compromised or provide details regarding how unauthorized individuals obtained access to official communication channels.
Details of Compromised Information
The unauthorized data disclosure encompassed extensive personal identification and financial details. Exposed information included customers’ complete legal names, birth dates, professional occupations, residential addresses, contact email addresses, and telephone numbers.
Government-issued identification materials were also released, including passport documentation and driving licenses, alongside photographic selfies that users provided for account verification purposes. The company emphasized that biometric facial recognition data remained secure and was not part of the breach.
A substantial portion of the leaked data consisted of financial documentation. Complete bank statements, International Bank Account Numbers (IBANs), account creation dates, withdrawal histories, and comprehensive transaction records were transmitted to the unauthorized party.
Cryptocurrency-related information featured prominently in the disclosure. Bitcoin wallet reference identifiers were visible within the shared account statements. Detailed Bitcoin transaction histories were also exposed, creating privacy concerns for cryptocurrency holders whose blockchain activity can now be correlated with their verified identities.
The platform confirmed that sensitive security credentials including private cryptographic keys, account login passwords, and complete payment card numbers remained protected and were not included in the data breach.
Scope of Customer Impact
Blockchain investigator ZachXBT published the customer notification via Telegram on September 11, indicating that the security incident appears relatively limited in magnitude and may have specifically targeted affluent users. Revolut has not disclosed the precise number of individuals whose data was compromised.
The platform currently maintains a global customer base exceeding 80 million users. This figure represents the company’s entire user population rather than indicating the scale of those impacted by this particular security breach.
The notification provided to customers does not specify whether every affected individual had all categories of data exposed, nor does it explain the selection criteria used by the attackers.
Compliance and Security Implications
The United Kingdom’s Information Commissioner’s Office emphasizes that data security breaches create significant risks including identity fraud, financial scams, and monetary losses. Regulatory frameworks mandate that organizations report qualifying breaches within a 72-hour window and immediately inform impacted individuals.
The customer notice screenshot distributed by ZachXBT does not indicate whether Revolut has filed the required regulatory notifications or specify when the company discovered the fraudulent nature of the data request.
Beyond the internal customer communication, Revolut has maintained public silence regarding the incident. The organization has not revealed which governmental agency’s email infrastructure was exploited in the attack.
This security breach emerges during a period of significant growth for Revolut. The company secured provisional authorization for a United States banking charter from the Office of the Comptroller of the Currency on September 3. Additionally, the platform introduced EURR, its euro-pegged stablecoin offering, to select European market customers during August.
These business developments operate independently from the data exposure incident. Revolut has not indicated whether any United States-based customers were among those whose information was compromised.
Source: Parameter
ALERT: Revolut falls for a FAKE government request, exposing sensitive personal information of customers in a disturbing data breach.