Revolut Discloses Customer Financial Records Following Fraudulent Government Email Request

The incident became public after former Mt. Gox CEO Mark Karpelès posted excerpts of Revolut’s customer notice on Sept. 12, 2026, while on-chain investigator ZachXBT also highlighted the case on Telegram.
Revolut’s notice did not specify when the fraudulent request or disclosure occurred, identify the government agency or sender, explain how the unauthorized account obtained access to the agency’s domain, or provide a confirmed number of affected customers.
ZachXBT characterized the incident as likely limited in scale and suggested it may have targeted high-net-worth customers, although Revolut’s notice did not confirm either the size of the affected group or how customers were selected.
Before issuing a broader public statement, Revolut’s support account told a user, “We take data protection and privacy concerns very seriously,” but added no details beyond those in the customer notification.
Revolut disclosed sensitive customer data after responding to a fraudulent request that mimicked a legitimate government agency. The fake email came from an unauthorized account within the agency's official domain and passed authentication checks, convincing Revolut it was genuine BigGo Finance.
The exposed information included names, addresses, dates of birth, passports, identity documents, selfies, account statements, bank details, and complete Bitcoin transaction histories CryptoNews. Revolut did not publicly name the agency, identify the sender, or confirm how many customers were affected Glitchwire.
The fraudulent email originated from an unauthorized account created within a legitimate government agency's domain. It carried valid authentication credentials, making it appear authentic Glitchwire. Revolut's systems had no reason to suspect the request was fake. The company later contacted the real agency, which confirmed the account and sender were unauthorized.
Revolut responded by blocking the unauthorized email address and notifying regulators about the breach BigGo Finance. The company also implemented precautionary measures to prevent similar incidents. However, Revolut's official notice did not explain how the attacker gained access to the agency's email domain in the first place CryptoNews.
The leaked data included complete Bitcoin transaction histories for affected customers CryptoNews. Also exposed were passports, residential addresses, identity verification documents, and selfies used for account verification BloomBit. Bank account numbers, withdrawal records, and full account statements were also compromised. Notably, Revolut said facial biometric telemetry was not shared Glitchwire.
The incident became public on September 12, 2026, when former Mt. Gox CEO Mark Karpelès posted excerpts of Revolut's customer notice online BigGo Finance. On-chain investigator ZachXBT also highlighted the case on Telegram the same day CoinDesk.
Revolut's official notification did not specify when the fraudulent request occurred or how many customers were affected Glitchwire. The company also declined to name the government agency involved. ZachXBT suggested the incident was likely limited in scale and may have targeted high-net-worth customers, though Revolut never confirmed either claim CryptoNews.
Before issuing a broader public statement, Revolut's support account told one user: "We take data protection and privacy concerns very seriously," but provided no additional details beyond the customer notification BigGo Finance. The lack of transparency has raised questions about the full scope of the breach and whether customers were selectively targeted.
The incident involved an unauthorized disclosure of customer data by Revolut, not direct access to user accounts by the attackers BloomBit. There is no evidence that the fraudsters broke into customer accounts, stole cryptocurrency, or made unauthorized withdrawals. The breach appears limited to the information Revolut itself provided in response to the fake government request CoinDesk.
Publishers
34
Articles
24
Reach
58