A number of Revolut customers have reported receiving notifications that their personal and financial data — including Bitcoin transaction histories — was disclosed in response to a government request now believed to be fraudulent.
Fraudulent Request Used Legitimate-Looking Credentials
According to an email shared by onchain investigator ZachXBT, the request originated from an unauthorized email account that nevertheless used a government agency’s official domain and carried valid domain authentication credentials. The convincing appearance of the request may have led Revolut to process it without detecting the deception.
Scope of Exposed Data
The disclosed information is extensive. Personal details include customers’ full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Identity and verification records — such as passport or driver’s license copies and verification selfies — were also released.
On the financial side, the data covers account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin activity. The email specified that biometric facial telemetry data was not shared.
Experts Warn of Targeted Attack on High-Net-Worth Users
Security experts suggest Revolut may have failed to recognize the fraudulent nature of the request before releasing customer information. “While the incident is likely limited in size it seems to have been targeted at high net worth users,” ZachXBT said.
Revolut has not yet commented publicly on the reported data exposure.

