Revolut leaked customer data after mistakenly accepting a fake government request, exposing personal information including passports, IDs, and financial records.
Revolut, a UK-based fintech company, inadvertently shared sensitive customer data with cybercriminals after verifying a fraudulent request allegedly from a government agency, according to multiple reports. The breach compromised personal information such as passport details, driver’s licenses, biometric selfies, and financial records, including bank account numbers and cryptocurrency transaction histories.
How the Data Leak Occurred
The incident began when Revolut received a request purportedly from a government body, which appeared legitimate due to its use of a genuine domain and authentication protocols. The bank processed the query, transferring data to what it believed was an authorized entity. However, subsequent investigations revealed the request was a sophisticated phishing attack, with cybercriminals impersonating officials to access customer information.
The number of agencies with access to police Flock
According to reports, the fraudulent email passed initial security checks, including SPF, DKIM, and DMARC protocols, which are designed to verify email authenticity. Revolut confirmed it immediately blocked the suspicious address and notified regulators, but the damage was already done.
Company Response and Customer Impact
Revolut stated in a public statement that its systems and customer funds remained secure, but it acknowledged the breach of personal data. The company informed affected users and implemented preventive measures. However, the exact number of impacted customers and the full scope of the data exposed remain undisclosed.
The systems and customer funds were not compromised, Revolut said in a statement. We have taken all necessary security measures to protect our users. The company also mentioned it was cooperating with law enforcement and regulatory bodies to investigate the incident.
Fed, state agencies can access city plate reader data
Broader Implications and Industry Concerns

The breach has raised significant concerns about the security of digital financial services and the vulnerability of even well-protected institutions to social engineering attacks.
The company has already faced scrutiny over its compliance with financial regulations, including a conditional approval from the U.S. Office of the Comptroller of the Currency (OCC) for a national bank license.
Revolut transferred personal customer data to fraudsters
Additional Details from Source Material
The breach involved the exposure of data including passports, driver’s licenses, verification selfies, full names, dates of birth, occupation details, home addresses, email addresses, phone numbers, IBANs, bank statements, transaction records, and cryptocurrency activity. TechCrunch reported that the stolen data included personal identifiers, while The Block and Decrypt noted the disclosure of cryptocurrency transaction histories.
A blockchain researcher known as ZachXBT, who first identified the breach, stated that the attackers targeted wealthy users. The scale of the leak appears to be limited, but the sophistication of the attack highlights the risks of phishing schemes, ZachXBT said.

Revolut was founded in 2015 and has since grown to become one of the fastest-growing fintech startups. The company’s data leak occurred amid ongoing regulatory reviews, with the U.S. OCC granting conditional approval for a national bank license. The incident also drew attention from CoinDesk, which reported that the fraudulent request arrived via a government agency’s email domain, which had previously passed Revolut’s authentication checks.
Revolut confirmed that customer login credentials and passwords were not compromised. The company emphasized that it had taken steps to secure its systems and notified affected users. However, the exact number of customers impacted and the specific government agency involved in the phishing attempt were not disclosed.
