Revolut confirmed on September 12 that an unauthorized third party obtained customer information by submitting fraudulent requests that appeared to come from a government agency.

The requests were sent from an email account using a legitimate government domain, giving them enough credibility to pass through Revolut's process for handling official information requests.

The company describes the incident as a sophisticated external impersonation scam.

The disclosed information goes far beyond an email address

Notifications sent to affected customers describe a particularly sensitive collection of data.

Potentially disclosed information includes names, dates of birth, postal addresses, email addresses and telephone numbers.

Copies of identity documents such as passports and driving licenses may also have been shared, along with selfies used during identity verification.

Account statements, IBAN information, withdrawal records and transaction histories were also potentially included.

Bitcoin transaction histories were among the records

The cryptocurrency element makes the exposure more significant.

A customer notice made public by former Mt. Gox CEO Mark Karpelès, who said he was affected, specifically lists full transaction histories including Bitcoin transactions among the information that may have been provided.

That can reveal much more than balances.

When combined with verified identity information, withdrawal records and other account data, a Bitcoin history can make it easier to associate real people with activity that otherwise appears only under blockchain addresses.

This was not a conventional breach of Revolut's systems

That distinction is central to understanding the incident.

Revolut says its systems were not compromised and customer funds were unaffected.

Based on the information disclosed so far, an attacker did not penetrate Revolut's infrastructure and extract a customer database.

Instead, customer records were apparently released through a legitimate process for responding to authorities after the identity of the requester was successfully impersonated.

Technically, those are very different failures. For someone whose passport or financial history was disclosed, the practical consequences can still resemble an ordinary data breach.

A legitimate government domain is not enough authentication

Banks and financial technology companies routinely receive requests from courts, tax agencies and criminal-investigation authorities.

Revolut itself publishes a dedicated contact channel for court orders and official information requests.

The incident exposes a weakness in treating the technical origin of an email as sufficient proof that the person sending it has authority to obtain the requested records.

A compromised or improperly accessed government mailbox can make a malicious request appear legitimate without requiring any intrusion into the financial institution itself.

Revolut has not disclosed how many customers were affected

The company says only a limited number of customers were involved and that those individuals were contacted directly.

It has not published a specific figure.

Revolut also declined to identify the government agency whose domain was used or confirm whether the incident was restricted to one country.

Those omissions make the actual scale of the exposure difficult to assess for now.

The high-net-worth targeting theory remains unconfirmed

Onchain investigator ZachXBT publicly suggested that the operation appeared likely to have targeted wealthier Revolut users.

That interpretation may fit the type of financial information being requested, but Revolut has not confirmed it.

It therefore needs to be separated from the established facts: fraudulent requests came through a legitimate government domain, and sensitive customer information was disclosed.

Revolut says the email address has been blocked

After detecting the incident, Revolut says it blocked the email address involved and implemented additional security measures.

The company also notified the relevant government agency, law enforcement, data-protection authorities and financial regulators.

Investigators now need to establish how the legitimate government-domain account was used and whether an attacker directly controlled an official mailbox or exploited another mechanism capable of making the requests appear authentic.

The issue extends beyond Revolut

Crypto companies and fintech platforms hold unusually attractive combinations of information: verified identities, government documents, home addresses, banking details and complete financial histories.

Much of that collection is required by Know Your Customer and anti-money-laundering rules.

It also means that a successful disclosure can provide an attacker with a remarkably complete profile of an individual.

When cryptocurrency services are involved, those records may also help connect pseudonymous blockchain activity with real-world identities.

Trust was the attack surface

The Revolut incident is a reminder that cybersecurity is not limited to preventing unauthorized access to servers.

A perfectly legitimate internal process can become an attack surface when the person on the other end is not who they claim to be.

Encryption and access controls can protect a database. They do not replace independent verification that the authority requesting information is actually authorized to receive it.

This attacker did not need to steal the records. The attacker convinced their custodian to send them.