Revolut says KYC data and Bitcoin transaction histories may have been exposed after fake government request
Fake government request triggered Revolut data exposure
Revolut says an unauthorized third party may have obtained sensitive customer records by sending fraudulent requests from an email account on a legitimate government agency domain.
The company said a limited number of customers were affected and that it has contacted them directly.
The main facts so far
- Revolut said the unauthorized requests came from an email account on a legitimate government agency domain.
- The data that may have been exposed includes KYC details, identity documents, account statements and full transaction histories, including Bitcoin transactions.
- Revolut said it blocked the email address and alerted law enforcement, data protection authorities and financial regulators.
- Revolut did not disclose how many customers were affected or which government agency domain was used.
What information may have been exposed
A notification sent to affected customers said names, dates of birth, postal and email addresses, telephone numbers, and copies of identity documents such as passports and driver's licenses may have been disclosed. Verification selfies, account statements and transaction histories may also have been included.
A copy of the notice posted publicly by former Mt. Gox CEO Mark Karpelès, who said he was among those affected, also lists account statements, IBANs, withdrawal records and full Bitcoin transaction histories as potentially shared information.
How Revolut responded
A Revolut spokesperson called the incident a "sophisticated external impersonation scam" and said the company blocked the email address after identifying it. Some affected customers reported receiving emails on Friday, the company said.
Revolut also said it alerted the relevant government agency, law enforcement, data protection authorities and financial regulators.
What is confirmed and what is still unknown
Revolut has confirmed that an unauthorized third party used a government agency email domain to request customer information, that the number of affected customers was limited, and that it contacted those customers directly. The company said its systems and customer funds were not affected.
It is still unclear how many customers were affected, whether the incident was confined to one market, and which government agency's domain was used. The notification says information "may have" been exposed, so it is not confirmed exactly which records were viewed or taken.
Onchain investigator ZachXBT speculated that the attack may have targeted high-net-worth users, writing, "While the incident is likely limited in size it seems to have been targeted at high net worth users." That claim is not confirmed.
Why the incident matters
Revolut is expanding its banking and crypto operations. Earlier this month, it received conditional approval from the U.S. Office of the Comptroller of the Currency to pursue a national bank charter in the United States. The proposed bank is expected to offer traditional banking products alongside stablecoin services.
The breach also shows how a trusted government domain can be used in an attempt to obtain private customer records.
Similar incidents at other crypto firms
Revolut's case is the latest in a series of customer data incidents involving crypto and fintech companies.
Last month, wallet provider SafePal said a flaw in an order-tracking system exposed personal information belonging to about 39,798 customers. Trezor said last week that a breach at shipping provider ShipMonk affected about 67,000 more U.S. customers. Trezor also disclosed this week that a breach at a third-party email provider allowed phishing emails to be sent from its legitimate domain.