Overview
- Revolut confirmed on Saturday that it disclosed sensitive customer records after fulfilling what it believed was a legitimate government request.
- The fraudulent messages came from an email address using a genuine government agency domain and passed SPF, DKIM and DMARC checks, which led Revolut to treat the requests as authentic.
- Notified customers were told the leaked material may include full names, dates of birth, contact details, copies of passports or driver’s licenses, verification selfies, account statements and Bitcoin transaction histories.
- Revolut says a limited number of customers were affected, that it blocked the sender and alerted the impersonated agency, law enforcement and regulators, but it has not named the agency or given exact scope.
- Security experts warn the main risk is identity theft and targeted impersonation and that investigators urgently need to know whether the records contained external wallet addresses that would link real identities to on‑chain activity.