How Did the Revolut Data Exposure Happen?
Revolut disclosed sensitive customer information to an unauthorized third party after fraudulent data requests were submitted from an email account using the legitimate domain of a government agency.
The fintech company described the incident as a sophisticated external impersonation scam rather than a breach of its internal systems. Revolut said it blocked the email address after detecting the activity and stressed that customer funds and its underlying technology infrastructure were not compromised.
The attacker appears to have exploited the credibility of a trusted government domain to convince Revolut that requests for customer records were legitimate. The company has not identified the government agency involved, disclosed how the email account was compromised or said whether the fraudulent requests were concentrated in one country.
Revolut said only a limited number of customers were affected and that those customers have been contacted directly. It has not disclosed the total number of people whose information was shared.
What Customer Information May Have Been Exposed?
The information potentially disclosed was extensive. Notifications sent to affected customers said the data may have included names, dates of birth, postal addresses, email addresses and telephone numbers.
Copies of identity documents, including passports and driver’s licenses, may also have been shared, along with verification selfies used during account onboarding.
Financial information potentially exposed included account statements, IBANs, withdrawal records and complete transaction histories. Those histories could include Bitcoin transactions where customers had used Revolut’s crypto services.
Former Mt. Gox CEO Mark Karpelès said publicly that he was among the affected customers and shared a copy of the notification he received.
Onchain investigator ZachXBT said the relatively limited scale of the incident could indicate that attackers were selectively targeting wealthier customers. He said the exposure appeared likely to have focused on high-net-worth users, although Revolut has not confirmed that assessment.
Investor Takeaway
The immediate risk is less about direct access to Revolut accounts than the value of the exposed information for targeted fraud. Identity documents, account histories and crypto transaction records could give attackers enough information to build highly convincing phishing, impersonation or social-engineering campaigns against affected customers.
Why Does the Incident Matter Beyond Revolut?
The case shows how customer-data security can fail even when a financial company’s own infrastructure is not directly breached. Criminals increasingly target trusted third parties, email providers and official domains because communications from those systems are more likely to pass internal verification checks.
Revolut said it notified the relevant government agency as well as law enforcement, data protection authorities and financial regulators after discovering the fraudulent requests.
The incident is particularly sensitive because Revolut is expanding both its banking and digital-asset businesses. The company recently received conditional approval from the U.S. Office of the Comptroller of the Currency as it works toward establishing a national bank in the United States.
The proposed U.S. operation is expected to offer traditional banking products alongside stablecoin services. Revolut is also expanding its crypto business internationally and began introducing EURR, its euro-backed stablecoin, to selected customers in Denmark, Poland and Portugal in August.
The company said at the time that it served around 80 million customers globally and planned to extend the stablecoin across the European Economic Area.
Crypto Firms Face Growing Customer-Data Risk
Revolut’s disclosure follows several recent incidents in which crypto and fintech customers had personal information exposed without attackers gaining access to private keys or customer funds.
SafePal disclosed last month that a vulnerability in an order-tracking system exposed information belonging to approximately 39,798 customers, including names, contact details, shipping addresses and purchase records.
Trezor also said a breach involving logistics provider ShipMonk affected roughly 67,000 U.S. customers, exposing names, email addresses, phone numbers, shipping details and order information. The hardware-wallet company separately disclosed that attackers had used a compromised third-party email provider to send phishing messages from a legitimate domain.
These incidents create a different risk from a direct wallet or exchange hack. Customer funds may remain technically secure while attackers obtain enough personal and financial information to identify valuable targets and make later scams considerably more convincing.
For Revolut, the key unanswered questions are how the government-domain account was compromised, how many fraudulent requests were processed before detection and whether the affected customers were deliberately selected based on account balances or transaction activity.