
Revolut has notified 680 customers after cybercriminals used a legitimate government email account to obtain sensitive identity, banking and Bitcoin-related records.
Summary
- Financial Times reports Revolut notified 680 customers after fraudulent requests exposed identity and financial records.
- Attackers used a legitimate government agency email domain, while Revolut says its systems remained uncompromised.
- Exposed records included passports, addresses, verification selfies, account statements, IBANs and customer Bitcoin transaction histories.
- Britain’s Information Commissioner’s Office has opened an investigation after Revolut reported the incident to regulators.
- Former Mt. Gox chief Mark Karpelès said Revolut warned him his information was exposed Friday.
The Financial Times reported that the fintech contacted 680 people identified during its initial investigation, while Revolut itself has publicly described the affected group only as a “very limited” number of customers. The company has not released an official numerical count.
Revolut confirmed that an unauthorized third party submitted fraudulent information requests from an email account using a legitimate government agency domain. The company treated the requests as genuine before discovering the impersonation scheme.
Revolut data breach came through a legitimate government domain
Unlike an intrusion into Revolut’s own network, the incident involved information being released after deceptive requests reached the company through an apparently authentic government channel. Revolut described the episode as a “sophisticated external impersonation scam.”
A customer notice reviewed by TechCrunch said the communication carried valid domain-authentication credentials, which led Revolut to believe it had received a genuine government request. The company has not named the agency involved or explained publicly how the third party gained control of the government email account.
Revolut said it blocked the address once the fraud was detected and contacted the government agency concerned, law enforcement, data-protection authorities and financial regulators. A spokesperson maintained that “Revolut systems and customer funds are unaffected.”
The company’s public page for official information requests directs competent authorities and legal representatives to a dedicated court-orders address. It asks authorities to submit one email for each case, although Revolut has not publicly described which verification steps were applied to the fraudulent requests involved in the breach.
As crypto.news reported when the incident first emerged, on-chain investigator ZachXBT circulated a copy of a customer notification and said the incident appeared limited in size and potentially focused on high-net-worth users. Revolut has not confirmed that assessment.
Exposed data included identity files and Bitcoin activity
Customer notices reviewed by multiple outlets listed a large range of personal information that may have been disclosed. The records included full names, dates of birth, occupations, home addresses, email addresses and telephone numbers.
Copies of passports or driver’s licenses and the selfies submitted during identity verification were among the listed records. Revolut’s notice distinguished those verification images from biometric facial telemetry, which it said was not part of the information involved.
Financial information went beyond basic account details. Customer statements could contain IBANs, account-opening dates, account status, withdrawal records and complete transaction histories. For crypto customers, the material included Bitcoin transactions and wallet reference numbers shown in account records.
The notice did not state that private keys, account passwords or full payment-card credentials were supplied to the unauthorized requester. It listed categories of records that may have been disclosed, meaning the available evidence does not establish that every affected person had every listed category exposed.
The Financial Times later reported that former Mt. Gox CEO Mark Karpelès was among the affected customers. Karpelès said Revolut emailed him at 5:25 a.m. on Sept. 12 warning that his information may have been compromised.
Karpelès questioned why the fintech released the records even though the request came from a verified government address. His criticism represents his assessment of Revolut’s handling of the request and not a regulatory finding against the company.
Crypto.news has detailed Karpelès’ history as the former operator of Mt. Gox, the Bitcoin exchange that collapsed in 2014 following the loss of customer cryptocurrency.
Extortion claims emerge as customer files surface
People claiming responsibility for the incident have threatened to release customer information unless Revolut pays an extortion demand, according to the Financial Times and Recorded Future News. Revolut declined to comment to Recorded Future News on whether it had received or was responding to an extortion demand.
Recorded Future News reported that material circulated through a Telegram account claiming involvement in the incident. One customer whose information appeared in the material did not dispute its authenticity, while cryptocurrency entrepreneur Marc Zeller separately said information belonging to him had been exposed.
Parts of the attackers’ story remain unverified. The Telegram account suggested that the government email came from an Italian domain, but Recorded Future News said it could not confirm all details in the account’s posts. Italian authorities contacted by the publication had not responded, and the Telegram account was later suspended.
Revolut has not publicly identified the government agency whose email system was used. No official statement located as of Sept. 15 establishes how the account was compromised, whether credentials were stolen, or whether the same government email access was used against other financial institutions.
The FBI has previously warned companies about criminals obtaining access to law-enforcement and government email accounts and using them to submit fraudulent emergency data requests. Recorded Future News noted that similar tactics were used against technology companies during earlier attacks involving compromised law-enforcement accounts.
UK privacy regulator is investigating the disclosure
Britain’s Information Commissioner’s Office has opened an investigation after Revolut reported the incident, the Financial Times reported Monday. An investigation does not by itself establish that Revolut breached UK data-protection law.
Under ICO guidance, organizations generally must notify the regulator within 72 hours of becoming aware of a reportable personal-data breach. Where an incident creates a high risk to individuals’ rights and freedoms, affected people must be informed without undue delay.
Revolut said it directly contacted the customers it believed were affected. Its public statement says it notified the relevant government agency, enforcement bodies, data-protection authorities and financial regulators after identifying the fraudulent requests.
The case arrives months after Revolut received approval to operate a full UK bank. As crypto.news reported in March, Prudential Regulation Authority approval allowed Revolut Bank UK to begin operating with banking status and deposit protection for eligible customer deposits. Crypto trading remains outside that deposit-protection structure.
Revolut serves more than 80 million customers worldwide, according to the company figure cited by TechCrunch and Recorded Future News. The 680 people identified by the Financial Times represent the current reported count from the investigation and should not be treated as a final figure unless Revolut or regulators publish an updated total.
The ICO’s published guidance says investigators may examine the type of data exposed, the number of people involved, potential harm and the technical or organizational safeguards used before deciding whether regulatory action is warranted.




Be the first to comment