Revolut, one of Europe's largest fintechs, has notified customers that it released sensitive personal files to an unauthorized third party after processing a fraudulent "emergency" government data request — one that arrived from a legitimate government agency email domain and therefore passed the usual authenticity checks.

The incident was reported by CoinDesk on September 12 and corroborated by BeInCrypto, which said Revolut confirmed an unauthorized party had used a genuine government domain to submit the fraudulent information request. Blockchain investigator ZachXBT, who first flagged the leak publicly, said the disclosure appeared to reach a small group of users and looked aimed at wealthy ones. Former Mt. Gox CEO Mark Karpelès shared one of the customer notices on X the same day.

What Was Disclosed

According to the customer notices described across the three reports, the released material included:

  • Identity documents such as passports and driving licences
  • Facial verification selfies submitted during onboarding
  • Home addresses and phone numbers
  • IBANs, account statements and withdrawal records
  • Full transaction histories, including Bitcoin activity

Revolut says passcodes, login details, customer funds and biometric data were not exposed, and that no customer money was lost. That last distinction deserves scrutiny: the verification selfie itself appears in the list of disclosed items, while Revolut's statement on biometrics seems to refer to derived facial telemetry rather than the image customers submitted when opening the account.

How a 'Real' Email Carried a Fake Request

The mechanics matter for every compliance team, not just Revolut's. Email authentication standards — SPF, DKIM and DMARC — verify whether a message is authorized by the domain it claims to come from. They do not verify whether the sender has legal authority to demand customer records.

Because the fraudulent request originated from a genuine government agency domain, the message carried real credentials and passed the technical checks. The fraud lived inside the request, not in the sender field — a category of attack that no spam filter catches.

Revolut says it discovered the deception after contacting the relevant authority, then blocked the sender, alerted the agency, contacted police and notified data protection and financial regulators. The company has not named the agency, citing the ongoing police investigation, and has not disclosed how many customers were affected or when the data left its systems. It says it has since tightened how it verifies law enforcement and regulatory requests.

Why Bitcoin Holders Should Care

The core systems were not breached. This was a process failure — and for crypto users, arguably a more dangerous one than a classic exchange hack, because of what the data enables next.

Blockchain records alone contain no passport details. The risk materializes when a regulated platform's files connect verified identity to transaction activity: legal name, face, home address, IBAN and a history of Bitcoin withdrawals in one package. An attacker holding that profile does not need a seed phrase. A caller who can cite a genuine withdrawal and a real address can impersonate the bank, a regulator or the police with details that feel private because they once were.

The exposure pattern echoes other recent incidents where the compromise was of identity data rather than keys — from the Trezor and BitBox newsletter phishing wave to the email provider breach that preceded it. In each case the stolen asset was trust infrastructure, not cryptography.

The Fix Is Dull and Necessary

The remediation for this failure class is unglamorous: out-of-band verification for any request involving customer records. A call back through a known official number, a dedicated portal, a named officer confirmed outside the email thread — anything other than treating authenticated mail headers as proof of legal authority.

Two open questions will determine the real severity. First, scale: Revolut has not said how many customers were affected. Second, linkability: the company maintains an internal ledger for customer crypto exposure, and it should clarify whether the disclosed Bitcoin histories included external wallet addresses and transaction identifiers, or only internal account activity. Those two possibilities create very different levels of exposure for matching real identities to visible on-chain activity.

Until then, affected users should treat any unsolicited message that references their crypto activity — account recovery, compliance checks, wallet "security" transfers — as a likely impersonation attempt. No legitimate institution asks for a seed phrase, a password or a one-time code.