Revolut has told some customers that it disclosed sensitive data after treating a purported government records request as legitimate when it actually came from an unauthorized third party. The material handed over included customer identity data, account records and full transaction histories, with Bitcoin transactions explicitly named.
A trusted government domain appears to have been abused
The case has drawn attention in crypto circles because the issue was not described as a hack into Revolut’s own systems. Instead, the report says the attackers appear to have obtained access to an email account inside the infrastructure of a real government domain. That mattered because the messages passed SPF, DKIM and DMARC checks, the same controls commonly used to verify the source of email.
Revolut said the request came from an unauthorized account built within the infrastructure of a genuine government domain and carried valid domain authentication credentials. On that basis, the company said it “reasonably believed” the request was authentic at the time. Revolut later contacted the relevant authority to verify the request and then confirmed that the email account had not been authorized.
After that, the company blocked the sender address, notified relevant regulators and applied additional precautionary protections to affected accounts.
The disclosed data went well beyond basic login details
According to notices sent to affected customers, the scope of the disclosure was far broader than a typical account credential leak.
The identity data that may have been shared included names, dates of birth and occupations. Contact details included home addresses, email addresses and phone numbers. For some customers, copies of passports, driver’s licenses and selfie images submitted during onboarding were also included.
Revolut said the exposed material involved the images themselves and did not include biometric telemetry derived from facial images.
Financial information that may have been disclosed included IBAN details, account status, account opening dates, wallet reference numbers, withdrawal records and full transaction histories. The report says those records explicitly included Bitcoin transactions.
Revolut’s privacy policy says the company routinely stores government-issued identity documents, facial data in photo or video form, information tied to external crypto wallets and records related to customer transactions in order to meet KYC, anti-money laundering and fraud prevention obligations.
That leaves open a more serious risk than simple exposure of personal details: one party may now hold a customer’s real-world identity, address, financial account information and crypto activity trail at the same time.
No public sign of a Revolut system breach as of Sept. 12
Based on what has been made public, this does not resemble a conventional database intrusion. As of Sept. 12, there was no public sign that Revolut’s own systems had been compromised. There was also no evidence that customer passwords, payment card PINs or crypto private keys had been stolen, and no public report that customer funds had been directly moved because of the incident.
The weakness exposed here sits elsewhere: financial institutions can still be deceived when they process law-enforcement or government data requests and rely too heavily on email-domain-based trust.
Bitcoin history paired with KYC data raises a different level of risk
The crypto-specific concern is that Bitcoin transaction history was disclosed alongside real-name KYC records.
Blockchain addresses are usually pseudonymous. Outside observers can see transfers on-chain without necessarily knowing who controls an address. Once an attacker also has a passport name, home address, phone number, email address, Revolut wallet reference data and BTC transaction records, on-chain activity can be cross-checked against a real identity.
That is not the same as losing a private key, so the data alone would not allow someone to directly move Bitcoin. It could, however, raise the risk of targeted phishing, SIM swap attacks, account recovery fraud, fake customer support scams and even extortion attempts against wealthy clients.
On-chain investigator ZachXBT said the case appears limited in scale for now and suspected the targets may have been concentrated among high-net-worth customers. Even so, Revolut has not published the number of affected customers, so the idea that the campaign mainly targeted wealthy users remains ZachXBT’s assessment, not an official conclusion from the company.
As of Sept. 12, Revolut had still not disclosed how many customers were affected or the name of the government institution whose domain was abused. Other unanswered points include when the data was actually handed over, whether similar requests were sent to other banks or exchanges, and whether the information has since been sold, used in scams or applied to blockchain tracing.
Revolut’s scale makes the incident more sensitive
The timing matters because Revolut is no longer a small fintech startup. Company data cited in the report says it now has more than 80 million retail customers globally and has been adding roughly 1 million new customers every 17 days, with a target of reaching 100 million users by mid-2027.
At the end of 2025, Revolut had 68.3 million retail customers, up 30% year over year, and 767,000 business customers.
Its 2025 revenue rose 46% to 4.5 billion pounds, or about $6 billion. Pretax profit increased 57% to 1.7 billion pounds, or about $2.3 billion. Total customer balances climbed 66% to 50.2 billion pounds, or about $67.5 billion.
Earlier this month, the U.S. Office of the Comptroller of the Currency gave conditional approval to Revolut’s application for a U.S. national bank license. Reuters reported that the company has about 80 million customers worldwide and plans to launch U.S. banking operations as early as the first half of 2027, including checking accounts, credit cards, foreign exchange, cryptocurrency and stablecoin-related services.
Against that backdrop, any weakness tied to KYC handling or crypto transaction data processing carries larger regulatory and reputational consequences than it would for a smaller fintech.
“Legitimate government requests” are emerging as a security attack surface
The central lesson in the incident is that a financial institution may disclose highly sensitive information even without suffering a classic network intrusion if the source of trust itself is hijacked.
Requests from governments and law-enforcement agencies for KYC files, account records or transaction histories are a routine part of financial crime investigations. Revolut’s own privacy policy says it may share customer data with government authorities when required by law.
But if a financial institution treats a request as trustworthy simply because it comes from a real government domain and passes SPF, DKIM and DMARC checks, an attacker who first gains control of an email account on the government side may be able to borrow that legitimate identity to get past internal controls.
For high-net-worth customers with crypto exposure, the danger may exceed that of a standard password leak. Passwords can be changed. Cards can be canceled. A linked record containing a name, passport, facial image, home address and historical on-chain activity cannot realistically be reset once the correlation has been made.
The report argues that the Revolut case points to a need for more than email and domain verification when banks handle government and law-enforcement requests. It cites options such as independent callback procedures, digital signatures, dedicated government request portals and other out-of-band checks to confirm that the party asking for the data is in fact the agency it claims to be.

