Revolut disclosed that it released sensitive customer information to an unauthorized party after receiving a fraudulent data request impersonating a legitimate government agency. The request reportedly originated from an unauthorized account using an official agency email domain with valid domain-authentication credentials, causing it to be treated as legitimate. The number of affected customers, the impersonated authority, and the precise failure path have not been publicly confirmed.
The exposed records reportedly include passport or other KYC identity documents, facial-verification selfies, contact details, account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin-related activity. Revolut said its core systems, mobile app, customer accounts, and funds were not compromised; it blocked the email source, notified authorities, and contacted affected users. The combined identity and financial data creates elevated risks of identity fraud, targeted phishing and vishing, SIM-swapping, fraudulent account opening or direct debits, extortion, and persistent linkage between customer identities and blockchain addresses.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
Following the disclosure, Revolut said it blocked the unauthorized email source, notified relevant authorities, and contacted affected customers. Customer posts and screenshots describing the apparent fake-government-request vector circulated publicly on September 11–12.
The disclosed information reportedly included names, dates of birth, contact details, passport or driving-licence copies, identity-verification selfies, account statements, IBANs, withdrawal records, wallet references, and complete transaction histories including Bitcoin activity. Revolut stated that biometric facial telemetry was not involved or compromised.
Revolut notified affected customers that sensitive identity, KYC, contact, and financial data had been disclosed after it received a fraudulent request impersonating a government agency. The request reportedly originated from an unauthorized account using an official agency email domain with valid domain-authentication credentials; Revolut said its systems, customer accounts, and funds were not compromised.
During a four-week period spanning August to September, approximately 75% of scam reports in Jersey involved Revolut accounts, with roughly £180,000 reportedly lost.
A cybercrime-forum actor advertised 75 million alleged Revolut records for $500. Revolut reportedly found no indicators of compromise or valid identifiers in the offered samples.
A former Revolut employee was alleged to have threatened to leak a customer’s KYC data unless paid in cryptocurrency. Revolut reportedly referred the matter to law enforcement.
Revolut suffered a targeted social-engineering breach involving a phished employee credential. Data of 50,150 customers, including names, addresses, contact details, partial card data, and past transactions, was exposed.
Marc Zeller and Mark Karpelès stated that their customer data was exposed in Revolut’s fraudulent government-agency request incident. The suspected perpetrators appeared to have selected a limited number of high-net-worth customers, many involved in cryptocurrency businesses.
Lithuania’s State Data Protection Inspectorate investigated Revolut’s 2022 breach as the lead data-protection supervisory authority for Revolut’s EEA entities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
15 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcetherecord.media
Open sourcemalware.news
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcethecybersecguru.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.