• Revolut released customer passports, verification selfies, addresses, IBANs and complete transaction histories, including Bitcoin activity, after acting on a request it later concluded was fraudulent.
  • The request came from a mailbox inside a genuine government agency’s domain and carried valid authentication credentials.
  • Revolut has not named the agency or said how many people were affected. It describes the number as limited and says no funds were lost.

Customers of Revolut were told on Friday that their identity documents and full account histories had been sent to somebody outside the bank. The request that triggered it looked exactly like the ones banks receive from law enforcement every day, because it came from inside a real government agency’s email system.

A leaked email address is an annoyance. A passport scan paired with the selfie you took to verify it, your home address, your IBAN and a complete record of every Bitcoin transaction you have made is something else. You cannot change your date of birth, and you cannot un-publish a transaction history that is already on a public . Whoever holds that combination can match your name to your coins, work out roughly what you hold, and know where you live.

If you bank with Revolut and have not had an email, you are most likely not among the affected group. The company says the number is limited, though it has not put a figure on it.

What was disclosed

Close-up image of Portuguese passport and citizen card, essential for travel and identification in the EU.
Passports and national ID cards like these are among the identity documents Revolut is said to have handed over in response to the fraudulent request. Photo by Marta Branco on Pexels.

According to the notification sent to customers, the released information could include copies of a passport or driving licence, the verification selfie taken during onboarding, names, dates of birth, occupations, home addresses, phone numbers, IBANs and account statements. Withdrawal records and complete transaction histories, Bitcoin activity included, may also have gone out.

Revolut says it contacted the agency after the fact, concluded the request was not genuine, blocked the address and started notifying customers and regulators. It has not identified the agency involved.

We have not seen Revolut’s own statement or the customer notification. This account comes from CryptoSlate’s write-up, which is itself working from the notices sent to affected customers. Treat the specifics as one outlet’s reporting until the company publishes something directly.

Why the usual check didn’t catch it

Banks and regulated fintechs receive data requests from police forces, tax authorities and financial regulators constantly. The process is routine: a request arrives from an official channel, a compliance team checks that the sender is who they claim to be and that the legal basis is valid, and the data goes out. Customers are usually not told, because the whole point of many of these requests is that the subject doesn’t know.

The check that carries most of the weight is the one on the sender. Does the request come from a government domain, and does it carry the right authentication? Here it did both. The mailbox sat inside the genuine agency’s domain infrastructure, and the credentials were valid. Whoever sent it had a foothold in a real government email system, which means every automated signal a bank looks for pointed the right way.

That is the part worth pressing the firm on. If the only meaningful verification step is one that a compromised government mailbox defeats, a second check, a callback to a known number, an out-of-band confirmation before sensitive documents go out, is not an exotic ask. Revolut made exactly that call after the data had gone, when it contacted the agency and established the request was fake. The question is why that call was not made first.

What nobody has established yet

Revolut says no funds were lost, and there is no reporting that any money has moved. The number of affected customers has not been stated. The agency has not been named, and it is not clear whether the intrusion into its email system has been closed off or whether other institutions received similar requests.

Marc Zeller, founder of the Aave Chan Initiative, was among those criticising the disclosure publicly, and the incident has reopened an argument that predates it: how much identity data financial firms are required to hold, and how well that pile is defended once a government comes asking for it.

If you were notified

Report it to Action Fraud, the UK’s national reporting centre for fraud and cybercrime, and keep the reference number. Revolut is also required to notify the Information Commissioner’s Office, and you can complain to the ICO directly if you are not satisfied with how the firm handles it.

With a passport copy and address in circulation, a credit freeze with Experian, Equifax and TransUnion makes it harder for someone to open accounts in your name. Expect targeted approaches rather than generic spam: whoever holds this data knows your bank, your balance history and your name, which is enough to make a phone call sound convincing. Revolut will not ring you and ask you to move money to a safe account, and neither will the police.

On the crypto side, the exposed history links your identity to specific addresses permanently. Moving coins to fresh addresses does not erase what has already been published, but it does mean future activity is not automatically attached to the same record. Our self-custody guide covers how holdings are structured and where the practical trade-offs sit.

What to watch

Whether Revolut publishes a number. “Limited” is a word that covers a wide range, and the ICO notification will eventually force more precision than a customer email does. Whether the agency is named, and whether any other institution turns out to have received requests from the same mailbox, which would turn this from one firm’s verification failure into a broader problem with how government data requests are authenticated.