Smiley face
Weather     Live Markets

Revolut Faces Scrutiny After Customer Data, Including Bitcoin Transactions, Exposed in Alleged Phishing Attack

Revolut is facing mounting questions after a number of customers were informed that sensitive personal and financial information — including Bitcoin transaction histories — may have been handed over to a party posing as a government agency. The disclosure, communicated to affected users by email and later shared by prominent on-chain investigator ZachXBT, has sent ripples through both the fintech and cryptocurrency communities. At the centre of the incident is what appears to be a fraudulent government data request crafted with unusual sophistication, raising urgent concerns about how digital banks verify law enforcement inquiries before releasing private customer data. The development is particularly alarming for Revolut, a company that has aggressively positioned itself as a modern alternative to traditional banking and has made no secret of its ambitions to attract cryptocurrency users. For those caught up in the exposure, the implications could be long-lasting, as financial data and identity documents are among the most sensitive information a consumer can entrust to any financial institution.

A Forgery That Looked Genuine: How the Alleged Government Request Was Made

According to the email text shared by ZachXBT, the request was sent from an unauthorized email account that nevertheless used the government agency’s official domain, and it carried valid domain authentication credentials. This is a troubling detail because it suggests the message was not a crude impersonation or a run-of-the-mill phishing attempt. In technical terms, the email reportedly satisfied domain-level authentication checks, meaning it would have looked nearly indistinguishable from a legitimate communication sent by an actual government body. Email security protocols such as SPF, DKIM, and DMARC are designed to prevent spoofing, yet in this case the authentication signals were apparently valid enough to pass through automated filters and, crucially, human review. Security experts say this combination — a real-looking sender address, valid authentication, and a carefully worded request — is precisely the sort of attack that can slip through even in well-regulated institutions. The email asked Revolut to hand over a range of customer data in response to a government request that was believed to be legitimate at the time. It remains unclear how the attacker gained access to the official domain or why the request was not subjected to additional verification, but the incident has already triggered concerns about the broader vulnerability of the global financial system to similar requests.

The fact that the message was described as coming from an “unauthorized” account using a government domain adds another layer of complexity. It suggests that either a legitimate email account was compromised or that the attacker managed to create a new account within the domain infrastructure. In either scenario, the result was an email that would have looked entirely plausible to a compliance officer reviewing an incoming legal request. The request reportedly covered a wide range of personal and financial data, and it appears that the data was shared before anyone realized the request was fraudulent. This has led security researchers to question whether Revolut’s internal procedures for handling government data requests are sufficiently rigorous. In traditional banks, requests from government agencies are typically subjected to multiple layers of review, with legal teams verifying the authenticity of the request through direct contact with the issuing authority. The Revolut incident suggests that such protocols may have failed, or perhaps did not go far enough to account for the increasing sophistication of attackers who can weaponize authentication systems designed to add trust.

A Complete Identity Kit: What the Exposed Data Included

The data reportedly exposed in the incident reads like a complete identity theft toolkit. According to the notification shared by ZachXBT, the affected customers’ full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers were included in the data that was shared. In addition, identity and verification information — including copies of passports or driver’s licenses and verification selfies — was listed among the compromised material. These documents are especially dangerous in the wrong hands because they can be used for identity fraud, loan application scams, and even the creation of new financial accounts in the victim’s name. Verification selfies, in particular, have become a target for cybercriminals because they can be used to bypass facial recognition checks at other financial institutions. The fact that this information was reportedly shared in response to a fraudulent request rather than a direct hack of Revolut’s systems is cold comfort; for the affected users, the risk is the same. Their personal details are now in the hands of an unknown third party, and it may be extremely difficult to determine the full extent of the misuse.

The financial data included in the exposure is no less concerning. The notification reportedly listed account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin activity. For many customers, particularly those who have used Revolut as a gateway into cryptocurrency, this level of transparency would be extremely damaging if it fell into the wrong hands. Account statements and transaction histories reveal not only how much money a person has, but also how they spend it, where they send it, and with whom they do business. The inclusion of IBANs is also significant, as these can be used to facilitate unauthorized transactions or to target victims for further phishing campaigns. Because the data was already shared, there is no way to “unshare” it, and affected customers may face a lengthy battle to protect their financial identities going forward.

Bitcoin Transaction Data: A Red Flag for Crypto Users

One of the most striking aspects of the reported exposure is the inclusion of full transaction histories, specifically Bitcoin activity. This has resonated deeply in the cryptocurrency community, where data privacy is highly prized and where the ability to transact without the prying eyes of third parties is often seen as a core value. The exposure of Bitcoin transaction data is uniquely damaging because blockchain transactions are permanent, transparent, and publicly auditable. While a traditional bank statement might reveal a transfer from one account to another, blockchain data can be followed indefinitely, and on-chain analysts — including ZachXBT himself — regularly use clustering techniques to link wallet addresses to real-world identities. If an attacker can connect a Revolut transaction history to a Bitcoin address, they may be able to trace the flow of funds into and out of that address, potentially mapping out a user’s entire cryptocurrency portfolio. This can expose users not only to financial losses but also to targeted extortion, harassment, or physical security risks in extreme cases.

The fact that Bitcoin data was included in the request suggests that the attacker may have been specifically interested in identifying cryptocurrency holders among Revolut’s customer base. Ledger and other crypto firms have faced similar threats in the past, but the Revolut case illustrates how a traditional financial services provider can become a vector for crypto-related surveillance and theft. Even though the email stated that biometric facial telemetry data was not shared, the other information exposed was more than sufficient to compromise a user’s financial identity. Biometric facial telemetry — a form of identity verification data that records facial movements and expressions — might provide an additional layer of identity verification, but its absence was little more than a detail in a much broader and more damaging disclosure. For cryptocurrency users, the exposure of transaction histories linked to identity documents creates a devastating combination: it tells the attacker not only who you are, but also what you own, where you have transacted, and how much wealth might be accessible through targeted scams or extortion.

ZachXBT Weighs In: A Targeted Attack on High-Net-Worth Users

ZachXBT, the on-chain researcher who first surfaced the email text, has suggested that the incident was not a random or widespread breach but rather a carefully targeted operation. “While the incident is likely limited in size, it seems to have been targeted at high net worth users,” he said in a post accompanying the disclosure. This assessment has significant implications for how the attack should be understood. If the goal was to identify wealthy individuals, then the attacker likely had a specific objective in mind, whether that was extortion, fraud, or long-term intelligence gathering. High-net-worth individuals are frequent targets of sophisticated criminal enterprises because they offer a larger financial reward with a single successful hit. The fact that the request was crafted to look like an official government inquiry further suggests a deliberate, well-resourced attempt to bypass standard compliance procedures. ZachXBT’s comment has prompted a wider conversation about whether Revolut’s risk management team was sufficiently alert to the possibility of manipulated legal requests, and about the broader responsibility of financial institutions to protect their most vulnerable and highest-value clients.

Security analysts who reviewed the email text have expressed similar concerns. Many have pointed out that the request was not a typical “spray and pray” phishing email sent to thousands of recipients; it was a targeted, personalized demand crafted to trigger a specific action. The fact that the sender used a government domain and valid authentication credentials indicates that the attacker had access to fairly advanced infrastructure or had compromised a legitimate email account. This is a level of sophistication that can outmaneuver standard security training, which typically focuses on how to spot grammar errors and suspicious links. In this case, there were likely no obvious red flags, and the request may have appeared entirely legitimate to the employees who processed it. The incident also highlights the risks associated with “compliance-driven data sharing,” where the fear of obstructing a government investigation can lead institutions to err on the side of compliance rather than caution.

Revolut Silent as Questions Mount Over Data Security

Revolut has yet to comment publicly on the reported data exposure, and it remains unclear whether the company has contacted affected customers directly or whether it has notified data protection regulators. This silence has not gone unnoticed inside the cryptocurrency and fintech communities, where the story has been shared extensively since ZachXBT published the email text. Many are asking difficult questions about how the request was validated, who approved the data transfer, and what steps have been taken to prevent a similar incident in the future. Data protection regulators across Europe and the United Kingdom are likely to take a strong interest in the case, particularly because Revolut operates as a licensed electronic money institution and holds data subject to strict regulatory requirements. If it is determined that the company failed to adequately verify the legitimacy of the request, it could face fines, compliance orders, or increased regulatory oversight.

This incident should also serve as a sobering reminder to users of modern financial technology platforms. While fintech companies often offer greater convenience and faster innovation than traditional banks, they can also become attractive targets for cybercriminals. The Revolut case shows that a breach does not have to involve a hack of an internal database; it can happen through a simple, well-crafted request that leans on the very systems designed to protect consumers. As customers, we place an enormous amount of trust in financial institutions, believing that they will guard our data with the highest standards of care. When that trust is broken, the damage goes far beyond the immediate loss of privacy. It undermines confidence in the digital economy and raises uncomfortable questions about the limits of institutional security.

For those affected by this disclosure, the next steps are critical. Monitoring bank accounts and credit files is no longer enough; individuals must also watch their cryptocurrency wallets, be suspicious of unsolicited communications, and consider freezing their credit with major bureaus. Identity monitoring services can help detect some forms of fraud, but they cannot prevent the use of passport copies or verification selfies in synthetic identity theft. Meanwhile, Revolut will need to act quickly if it hopes to restore public confidence. A transparent explanation of what happened, how many customers were affected, and what measures are being implemented would be a start. A full technical review of how government requests are authenticated, perhaps including direct verification through known phone lines or secure government portals, would be an even better signal. This is a developing story, and the broader implications for fintech security and government data requests are only beginning to emerge.

Share.
Leave A Reply