-
Revolut confirmed that a fake request came from a real government email domain.
-
The data may include IDs, selfies, addresses, IBANs, bank records, and Bitcoin history.
-
Revolut says a small group of users was hit. Claims of a wider leak and ransom demand are not yet confirmed.

Revolut has reportedly confirmed a data breach after scammers used a real government email domain to ask for customer data. The attackers did not break into Revolut’s main network. They used a trusted email account to make false requests look real.
Revolut said an unknown person used a real agency domain to send the requests. The firm then shared data in response.
That is why the case is different from a normal hack. The attacker did not need a software flaw in Revolut. The attack used trust in a process that can unlock sensitive records. That makes the case a warning for any bank that accepts data requests by email.
What Data May Have Leaked?
The leak may go far beyond names and email addresses. A customer notice seen by our research team indicates it may include names, birth dates, home addresses, emails, and phone numbers. It may also include passport and driving licence copies. The list also covers ID selfies, bank statements, IBANs, withdrawal records, and full account history.
For some users, that history may include Bitcoin deals. Revolut has not said how many users were hit. It has also not named the agency.
The most striking part of the case is the email domain. The attackers did not use a fake domain that only looked like a government site. They used the real domain of a government agency. Also, the messages passed email checks. That made the requests look valid.
But an email check does not prove that the person behind an account has the right to ask for private data. Revolut called this a “sophisticated external impersonation scam.” The firm has not said how the attacker got access to the government account.
Bitcoin Users Face a Bigger Privacy Risk
The Bitcoin data adds a major privacy concern. Bitcoin transactions are public. But a wallet address does not always show the name of its owner.
A firm like Revolut can hold that missing link. If the stolen records join a real name to wallet activity, an attacker may trace past Bitcoin use to that person. That could show wallet addresses, past deals, and times when a user moved large sums.
There is no public evidence that private keys were leaked. There is also no sign that the incident let the attackers take funds from customer wallets.
On-chain researcher ZachXBT said the case looked small and may have focused on wealthy users. That is his view, not a confirmed finding from Revolut.
Attackers Claim they are Now Leaking Data
The case may not end with the data sent to the scammers. International Cyber Digest said on September 13 that the attackers had begun posting customer data and asking Revolut to pay. These claims need context.
Revolut has confirmed the data exposure. But it has not confirmed the names in the alleged leak. It has also not confirmed the wider ransom claims. Files posted online do not prove that every file came from this case.
Similar unverified breach claims have appeared on other platforms. A massive Telegram data breach claim has also emerged online, although its authenticity remains unverified, showing why leaked files and threat-actor claims require independent confirmation.
The core facts are clear. An unauthorized person used a real government agency domain to send false requests. Revolut answered those requests and shared customer data. Once the firm found the abuse, it blocked the address and alerted the right groups.
Revolut says the incident didn’t affect its systems and customer funds. So this was not a direct theft of funds, nor was it a known takeover of customer accounts. The failure came in the way Revolut checked a request for customer data. That matters because a company can keep its main network safe and still give data to the wrong person.
A Warning for Banks and Fintech Firms
This case shows why an email address is not enough proof. Banks and fintech firms get data requests from police and other state bodies. They need ways to check that each request is real.
For customers, the next risk is targeted fraud. Anyone who got a Revolut notice should be wary of odd calls, emails, and texts. A scammer with ID and bank data can make a fake message look very real. Crypto users should take extra care. A leak that links a name to public Bitcoin activity can expose far more than a normal email leak.
Although Revolut has confirmed the data exposure, key facts are still missing. The number of affected users or the name of the agency remains a mystery. The company has also not provided a full account of how the fake requests passed its checks. Until those details emerge, claims about a much wider leak are just mere rumors.