Overview
- Revolut says it fulfilled a deceptive request that used a legitimate government agency email domain and has confirmed the disclosure after the incident was flagged by on-chain investigator ZachXBT, who posted about it Friday.
- The company’s customer notice and reporting say the material supplied included names, dates of birth, contact details, copies of passports or driver’s licenses, verification selfies, account statements, and Bitcoin-related transaction records.
- Technical details in reporting show the email passed SPF, DKIM and DMARC checks, which suggests the attacker had access to an unauthorized mailbox inside the agency’s domain rather than merely spoofing the sender address.
- Revolut says it blocked the sender, contacted the government agency, alerted law enforcement and regulators, and has notified affected users while stressing that private keys, passwords, full card numbers and customer funds were not exposed.
- Security experts warn that linking verified identity documents to crypto transaction histories can enable long-term impersonation and account-recovery scams, so affected customers should verify any Revolut messages in-app and secure their recovery email and phone number while regulators investigate the scope.