Revolut has confirmed it released sensitive customer data in response to a fraudulent government request, after crypto investigator ZachXBT publicized user notices that detailed what happened. The incident didn’t involve any breach of Revolut’s systems or a loss of customer funds. Instead, the failure appears to have happened inside the company’s compliance and disclosure process.
Revolut says an external actor impersonated a government agency, using an official-looking domain email to submit an information request for specific customer records. That request got through at least some of the usual authenticity checks and led to staff sharing files that included passports or other identity documents, home addresses, and full Bitcoin transaction histories. Other affected records reportedly included verification selfies and banking details, tying know-your-customer data directly to a user’s crypto transactions.
This is less about consumer wallet safety and more about how platforms verify the legitimacy of official data requests before making disclosures that can’t be reversed. Revolut says the sender was blocked after the fraud was detected and regulators were informed. For any firm handling crypto, this serves as a test of institutional controls: do staff have the right tools and procedures to tell a true legal demand from a sophisticated fake. The case could prompt scrutiny across fintech, especially if the attacker leveraged a genuine government domain.