Revolut Discloses Data Breach After Fraudster Used Government Agency Domain to Fake Customer Data Request

Somewhere inside Revolut’s compliance operation, a request arrived that looked exactly like the kind of thing the team is built to handle without hesitation: an information demand from a government agency, sent from that agency’s own official email domain, carrying valid authentication that made it indistinguishable from a routine lawful request. That ordinariness is precisely why it worked. Revolut has now confirmed that an unauthorized third party gained control of an email account sitting inside a legitimate government agency’s domain and used it to submit fraudulent requests for customer data — and that the fintech firm fulfilled them.
The company disclosed the incident as what it called “a sophisticated external impersonation scam,” in which the attacker’s email carried the government agency’s genuine domain authentication credentials, giving Revolut’s systems and staff no obvious signal to distinguish it from an authentic request. It was only after Revolut had already handed over data that it independently contacted the agency to verify the request — and discovered the account inside the agency’s own domain had never been authorized to send it.
What went out the door in response covers a wide surface area. Revolut says the exposed information may have included account statements carrying IBAN and wallet reference numbers, withdrawal records, and full transaction histories — explicitly including Bitcoin activity — alongside identity details such as birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver’s licenses. The company says its core systems and customer funds were not affected, and that only a “limited” number of customers were impacted, though it has declined to say how many or to identify the agency whose domain was compromised.
On-chain investigator ZachXBT, who helped circulate word of the breach, has speculated that the scale and specificity of the request suggest the attacker was targeting high-net-worth customers rather than running a broad, indiscriminate scrape — a theory consistent with singling out Bitcoin transaction histories and full account statements rather than requesting bulk account lists. Revolut says it has blocked the compromised email address, notified affected customers directly, and alerted the impersonated government agency, law enforcement, and financial regulators.
The incident lands as an uncomfortable case study in a specific kind of failure: not a hacked database or a stolen password, but a process built to trust a legitimate-looking channel that turned out to have been quietly compromised at the source. For crypto holders on any platform, it’s a reminder that transaction history tied to a real-world identity is only as private as the weakest verification link in every institution that can be compelled — or fooled — into handing it over.
Readers looking to understand how self-custody reduces this kind of third-party exposure can start with coin680’s Bitcoin Academy.
This article is for informational purposes only and is not financial advice. Details of the incident, including the number of affected customers and the identity of the impersonated agency, have not been fully disclosed and may be updated as investigations continue.
