Key Takeaways
Revolut disclosed customer data after attackers used a fraudulent request from a legitimate government email domain.
Exposed information reportedly includes identity documents, contact details, account records and Bitcoin transaction histories.
Attackers have begun publishing customer data and reportedly threatened further releases unless Revolut pays a ransom.
The Revolut Data Breach: What We Know so Far
Revolut has confirmed that a fake government request led it to hand over sensitive customer information to an unauthorized third party.
The incident did not involve hackers breaking into Revolut's systems or taking money from customer accounts. Instead, the attackers reportedly used an email account connected to a legitimate government domain to make their request look genuine.
The situation has since escalated, with the attackers beginning to publish some of the stolen information online. This turns what was initially a case of social engineering and unauthorized data disclosure into a more immediate risk for affected customers.
Once sensitive information is publicly exposed, it can potentially be used for further scams, phishing attempts, identity theft, or other targeted attacks. It also means that even customers whose accounts and funds were never directly compromised may still face consequences from the breach.
According to Revolut, the email passed its domain authentication checks. The company believed it was a real government request and provided the requested customer information.
Revolut later discovered that the request was fraudulent.
“Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” a company spokesperson said.
The company said it blocked the address after discovering the fraud and notified the relevant government agency, law enforcement and regulators.
Revolut said its systems and customer funds were not affected. The company has not disclosed the exact number of customers impacted, describing it only as “limited.” However, a Financial Times report estimates that around 700 accounts were affected.
According to the latest reports, Revolut serves more than 80 million customers worldwide, putting the incident’s scale in relatively low proportion to its overall customer base.
Customer notices reportedly sent by Revolut listed a wide range of information. This included names, dates of birth, occupations, home addresses, email addresses and phone numbers.
The information also reportedly included passports and driving licenses, as well as selfies submitted during identity verification.
Financial information was also exposed. Reports based on Revolut's customer notices say this included IBANs, account statements, withdrawal records and complete transaction histories, including Bitcoin activity.

The data stolen from Revolut — MalwareBytes
Revolut has said that biometric facial data was not exposed. In other words, the facial template used by its systems was not part of the information disclosed. However, the actual verification selfies were reportedly included.
The exposure of Bitcoin transaction histories makes the incident especially serious for users.
A Bitcoin address may not directly reveal who owns it. But once an exchange or financial platform connects an address to a customer's identity, that connection can become very valuable to an attacker.
In this case, the reported combination of identity documents, home addresses and Bitcoin transaction histories could give attackers a detailed picture of a person's digital asset activity.
For example, someone could potentially see how much bitcoin a customer has moved through Revolut, when transactions took place and which addresses were involved.
Blockchain analysis could then be used to follow those transactions further.
On-chain investigator ZachXBT, who helped bring attention to the incident, said the breach appeared to be limited in size and may have focused on high-net-worth customers.
Revolut has not confirmed that wealthy customers were specifically targeted.
The incident later appeared to take another turn. Reports said the attackers began publishing some customer documents and verification selfies online.
The leaked material reportedly included documents belonging to tennis player Alexander Shevchenko and Felix Römer, CEO of gambling company Gamdom.
The attackers reportedly threatened to publish more customer information every day unless Revolut paid them.
Some reports put the ransom demand at 10,000 bitcoin. However, that figure has not been independently confirmed, and Revolut has not confirmed the amount.

Max Karpis on X
The attackers have also reportedly claimed that they had been collecting information for months and had obtained records from customers in several countries. Those claims have not been independently verified either.
The full number of affected customers remains unknown.
One of the most important parts of the incident is how the attackers got Revolut to release the information.
An authenticated email does not necessarily prove that the person using the account is authorized to make the request.
Hacking into authorized email servers has become increasingly common. In a recent, similar incident, hackers compromised the email provider used by digital asset wallets such as Trezor and BitBox, allowing them to send phishing emails that passed all security checks.
This is the key weakness exposed by the incident. An attacker who gains access to a legitimate mailbox, or an account within its domain, can potentially make a request that looks genuine even when it is not.






