Revolut has warned a limited number of customers that sensitive personal and financial records may have been disclosed after an unauthorized party used an email account hosted on the domain of a legitimate government agency to submit fraudulent information requests.
The fintech company said the potentially exposed material included names, dates of birth, postal and email addresses, telephone numbers, identity-document copies, verification selfies, account statements and transaction histories. Some affected users may also have had banking details disclosed, including IBANs, withdrawal records and full transaction histories that could include Bitcoin activity.
The incident did not involve a breach of Revolut’s customer-facing systems or an impact on customer funds, the company said. Instead, the disclosure appears to have resulted from an impersonation operation that exploited the trust attached to a genuine government-domain email address.
Revolut said it identified and blocked the email address, contacted affected customers directly and notified the relevant government agency, law enforcement, data-protection authorities and financial regulators. The company did not disclose the number of customers affected, the country or market involved, the government domain used, or the agency connected to it.
Some customers said they received Revolut’s notification emails on Friday. Mark Karpelès, the former chief executive of the now-defunct Bitcoin exchange Mt. Gox, publicly shared a copy of the customer notice and said he was among those affected.
Financial histories create a more targeted risk
The range of information described in Revolut’s notice could give fraudsters far more than the contact details usually associated with a data breach. Identity-document images and selfies could be useful in account-takeover attempts or social-engineering schemes, while account statements and transaction data could help criminals tailor messages to a customer’s financial circumstances.
For cryptocurrency users, records identifying Bitcoin transactions or withdrawals may create particular privacy concerns. A criminal who knows that a target has used cryptocurrency services, holds a large account balance or has made substantial transfers could craft more credible phishing messages, impersonate compliance teams or claim that an account requires urgent action.
Blockchain investigator ZachXBT drew attention to the incident and said it appeared to have targeted high-net-worth users. Revolut has not publicly characterized the apparent victim profile or said whether the fraudulent requests sought records associated with particular account types.
The use of a government-linked email domain is central to the case. Financial companies regularly receive legally framed requests for records from regulators, police bodies and other authorities. An attacker able to send messages from a trusted domain can attempt to bypass the suspicion that would meet an email from an unknown address, especially if the request mimics standard official language.
Revolut’s statement suggests that the company’s internal systems remained intact, but the episode exposes a different pressure point: the process through which companies validate external requests for customer information. The safeguards required for those requests extend beyond password security and network defenses, since the deciding factor can be whether staff can reliably verify the sender and the legal basis for disclosure.
Disclosure arrives during banking and stablecoin expansion
The customer-data warning comes as Revolut adds regulated banking and cryptocurrency products across several markets. The company recently received conditional approval from the U.S. Office of the Comptroller of the Currency as it pursues plans for a national bank in the United States.
Revolut has said its proposed U.S. bank would offer conventional banking products alongside stablecoin services. The effort follows an application earlier this year for a de novo banking charter, which would allow the company to establish a new bank rather than acquire an existing institution.
In Europe, Revolut began a phased rollout of EURR, its first euro-backed stablecoin, in August for selected customers in Denmark, Poland and Portugal. The company said it had 80 million customers globally and planned to extend access to the stablecoin across the European Economic Area.
Its trading services have also been moving toward more automated interfaces. In July, the company connected its Revolut X platform to third-party artificial-intelligence assistants, including Anthropic’s Claude and Google’s Gemini, allowing customers to analyze markets and place trades through natural-language prompts.
Those product additions place more financial activity, identity data and transaction records inside the same consumer platform. A fraudulent records request involving a customer with bank, payments and crypto activity could expose a fuller picture of an individual’s finances than a request limited to a single-purpose service.
Recent third-party incidents show recurring exposure routes
Revolut’s case follows several recent data-security incidents involving cryptocurrency companies and their outside providers. SafePal said last month that an order-tracking flaw exposed customer names, contact information, shipping addresses and purchase information for about 39,798 people. The wallet provider said private keys, seed phrases and customer funds were not affected.
Trezor separately said a breach at shipping provider ShipMonk affected about 67,000 U.S. customers. According to Trezor, exposed information included names, email addresses, phone numbers, delivery addresses and order numbers.
Trezor also said this week that attackers exploited a third-party email provider to send phishing emails from Trezor’s legitimate domain. That incident, like the Revolut disclosure, illustrates how a trusted communication channel can become the mechanism for a fraud attempt even when the core product infrastructure has not been compromised.
Shipping and email-service incidents can pose distinct risks for hardware-wallet users because physical address data may identify people who own self-custody equipment. Financial-record disclosures bring another layer: transaction histories and withdrawal information can allow criminals to select targets and make deceptive communications appear personally relevant.
Affected Revolut customers should treat unexpected messages about account security, document verification, transaction reversals or cryptocurrency withdrawals with heightened caution. Communications that appear to come from Revolut, a government agency or a wallet provider can be independently checked by opening the company’s official app or manually entering its website address, rather than following links in an email or text message.
Revolut has not indicated that customers need to take action beyond reviewing its direct notification. Its disclosure nevertheless adds to a growing pattern in which attackers seek customer data through service providers, business processes and trusted digital identities rather than attempting to penetrate wallets or banking systems directly.
Worried about breaches like this? Strengthen your defenses with Toobit’s crypto safety standards every trader should know today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
