Revolut says fake government email exposed some customer data

Revolut says fake government email exposed some customer data

N
News Editor
2026-09-13 09:27:21
Revolut said some customer data was disclosed after the company received fraudulent information requests that appeared to come from a government agency. The exposed material included passport copies, verification selfies and full transaction histories, according to the report. International Cyber Digest said on X that the requests came from a legitimate government agency email domain and passed Revolut’s authentication checks, though the company later determined they were not genuine. Revolut said affected customers were notified on Friday. A spokesperson told Cointelegraph on Saturday that the incident involved a sophisticated external impersonation scam in which an unauthorized third party used a legitimate government agency domain email to submit fraudulent requests for information. Revolut said it blocked the address after detecting the issue, alerted the relevant government agency, and informed law enforcement agencies and financial regulators. The company added that its systems and customer funds were not affected and that only a limited number of individuals were impacted. The incident also drew criticism on X over mandatory data-sharing practices, while ZachXBT reportedly said the case appeared limited in size and targeted at high-net-worth users.

Revolut said sensitive customer data was disclosed after it received fraudulent requests for information that appeared to come from a government agency. The exposed records included copies of passports, verification selfies and full transaction histories.

According to International Cyber Digest on X, the requests were sent from a legitimate government agency email domain and passed Revolut’s authentication checks. Revolut later concluded the requests were not authentic, and customers whose information was compromised were notified on Friday.

A company spokesperson told Cointelegraph on Saturday: "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."

The spokesperson said Revolut blocked the address after detecting the issue and alerted the relevant government agency. It also notified law enforcement agencies and financial regulators.

"Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support," the spokesperson said.

Crypto sleuth ZachXBT reportedly said he believed the incident was limited in size and appeared to target high-net-worth users.

The episode sparked discussion on X, where some users criticized the current system of mandatory information sharing. Marc Zeller wrote that he woke up to find all of his data leaked by Revolut and added: "Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way."

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.