- Revolut data breach follows fraudulent information requests sent through a legitimate government agency email domain.
- Potentially exposed records include identity documents, verification selfies, account statements and Bitcoin transactions.
- Revolut contacted affected customers and authorities, saying its systems and customer funds were unaffected.
Revolut confirmed on September 12 that it disclosed customer information to an unauthorized party following fraudulent government information requests. The requests came through a legitimate government agency email domain, according to a spokesperson.
The Revolut data breach affected a limited number of customers, the company told TechCrunch. It contacted those individuals directly but did not disclose how many people were involved.
Revolut Data Breach May Include Identity and Bank Records
Customer notifications list names, birth dates, occupations, postal addresses, email addresses and telephone numbers among potentially disclosed information. Copies of passports or driving licenses and verification selfies may also have reached the unauthorized recipient.
Financial records potentially included account statements, IBANs, withdrawal details and transaction histories covering Bitcoin transactions. Revolut said the disclosure did not include biometric facial telemetry data.
Former Mt. Gox CEO Mark Karpelès shared a notification publicly and said he was among those affected. His account adds a named customer to reporting on the Revolut data breach.
According to the notice, the request carried valid domain authentication credentials. Revolut processed it under the mistaken belief that it represented a genuine government inquiry.
Company Blocks Email Address and Notifies Authorities
After identifying the Revolut data breach, the company blocked the email address used to request records. It also alerted the relevant agency, law enforcement, data protection authorities and financial regulators.
A spokesperson described the incident as a “sophisticated external impersonation scam.” The company said its systems and customer funds were unaffected.
Revolut declined to identify the government agency or clarify whether the incident affected customers in only one market. Its statement did not provide an exact customer count.
Meanwhile, investigator ZachXBT said the Revolut data breach appeared to target high-net-worth users. The company has not publicly confirmed that assessment.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. CoinCryptoNewz is not responsible for any losses incurred. Readers should do their own research before making financial decisions.



