Revolut exposed Bitcoin records after fake agency request


Revolut has disclosed customer identities and financial records, including Bitcoin transaction histories, after acting on a fraudulent request that appeared to come from a government agency.

Summary

  • Revolut said an unauthorized sender used an official government agency’s email domain.
  • The disclosed records included identity documents, verification selfies, and full transaction histories.
  • Bitcoin wallet reference numbers appeared in account statements listed in the customer notice.
  • ZachXBT said the incident appeared limited and may have targeted high-net-worth users.

According to a Revolut customer notice shared on Telegram by on-chain investigator ZachXBT, the request came from an unauthorized email account that used an official government agency’s domain. The message passed domain authentication checks, and Revolut said it believed the request was genuine when it provided the information.

Screenshot of ZachXBT’s Telegram post showing a Revolut notice about customer data disclosed after a fraudulent government request, including identity documents and Bitcoin transaction histories.
Source: Telegram/zachxbt

The notice does not name the agency or say how the unauthorized sender obtained access to its email domain. It also gives no date for the request or the disclosure. ZachXBT said multiple customers received an alert email on Friday, Sep. 11, but neither he nor the portion of the notice shown in his post gave a confirmed count of affected users.

How the fake request reached Revolut

In its account of the incident, Revolut said the email appeared to be a legitimate government request because it carried valid domain authentication credentials. The request was sent directly from an unauthorized account using the agency’s official email domain, rather than from an address made to look similar to it.

“As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request,” the notice said.

The wording describes an unauthorized disclosure made in response to a deceptive request. The notice does not say that an intruder entered Revolut’s systems, accessed customer accounts or withdrew funds. It does not identify the person who sent the request or say whether the agency has investigated the use of its email account.

ZachXBT described the incident as likely limited in size and said it appeared to have targeted high-net-worth users. Revolut’s notice, as shown in the screenshot, does not confirm either the size of the affected group or how the customers were selected.

What Revolut says it disclosed

Revolut listed customers’ full names, dates of birth, and occupations among the identity details provided. Contact information included postal addresses, email addresses, and telephone numbers.

The request also resulted in the disclosure of copies of identity documents, such as passports or driver’s licences, along with the selfies customers supplied for identity checks. Revolut drew a distinction between those images and biometric facial telemetry data, which it said was not involved.

Account statements formed another part of the disclosed material. According to the notice, the statements included IBANs, account status, account-opening dates, and Bitcoin wallet reference numbers. Withdrawal records and full transaction histories, including Bitcoin transactions, were also provided.

The notice lists categories of information that may have been disclosed; it does not establish that every affected customer had every type of record on file. Nor does it say that wallet private keys, account passwords or full payment card details were included. Bitcoin transaction histories are particularly relevant to crypto users because the notice places them alongside names and other account records in the information sent to the unauthorized requester.

Revolut serves more than 80 million customers globally, according to an August company announcement. That customer figure describes the size of its business, not the number affected by this disclosure.

What the records could mean for affected customers

The UK Information Commissioner’s Office says the possible consequences of a personal data breach include identity theft, fraud and financial loss. Its breach guidance calls for an assessment of the information involved and the likely harm to individuals; it does not establish that anyone has suffered those outcomes in the Revolut incident.

For a customer whose identity document and transaction records were both disclosed, the notice indicates that the recipient could have obtained a detailed account of that person’s finances. ZachXBT’s claim about wealthy users being targeted has not been confirmed by Revolut in the material shown, and no subsequent misuse of the records is documented there.

The regulator’s guidance also says organizations must report certain personal data breaches within 72 hours of becoming aware of them, where feasible, and notify individuals without undue delay when the risk to their rights and freedoms is high. The screenshot does not say whether Revolut has notified a regulator or when the company first learned of the unauthorized request.

In its U.S. security guidance, Revolut tells customers to use in-app support chat to check whether a suspicious contact is genuine. The company says it will not ask customers to share verification or security codes over the phone. The customer notice shown by ZachXBT does not report that such codes were disclosed.

Revolut’s U.S. and crypto operations

The incident comes during Revolut’s expansion of its banking and digital-asset services. On Aug. 26, the company began offering its euro-backed EURR stablecoin to selected customers in Denmark, Poland, and Portugal, with further European availability planned, as previously reported by crypto.news. The stablecoin rollout is separate from the customer-record disclosure.

Revolut’s U.S. plans provide context for American readers, although the notice does not identify any affected customer as being in the United States. On Sep. 3, the company received conditional approval for a U.S. bank from the Office of the Comptroller of the Currency. Its proposed Stamford, Connecticut, bank would receive about $95 million in initial capital and could open in 2027 if it obtains the remaining approvals.

For now, Revolut provides U.S. customer banking services through Lead Bank, according to the earlier report. The proposed national bank still needs deposit insurance from the Federal Deposit Insurance Corporation, Federal Reserve approval, and final OCC authorization before it can open.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *