Revolut allegedly exposed sensitive customer information after a fake government request, with ZachXBT warning about targeted high-net-worth users.
Revolut allegedly disclosed sensitive customer information after receiving fraudulent government information requests. On-chain investigator ZachXBT warned that the incident could have been an attack on high-net-worth individuals. Several customers were said to have been notified by e-mail regarding the incident.
What User Information Was Allegedly Exposed?
The leaked information may include identity documents and verification selfies, according to ZachXBT. Furthermore, the information allegedly affected contained full names, dates of birth, occupations, addresses, e-mail addresses and telephone numbers.
Related reading: Revolut Wins VARA Approval for UAE Crypto Services.
The exposure also included financial data associated with Revolut accounts. This is said to have included IBAN numbers, account statements, withdrawal records and full transaction histories.
Importantly, some of the transaction records reportedly contained Bitcoin transfers. Hence, the incident may pose further risks to customers that are active users of crypto services or hold large digital asset portfolios.
The incident is said to have started with the malicious actors sending government information requests to Revolut. The requests were apparently legitimate, as they were using a valid government domain and were passing domain authentication checks.
But Revolut later found out that the requests were fake. The company, therefore, allegedly gave out customer information to unauthorized parties before realizing that the requests were fraudulent.
The incident underscores the dangers of such attacks using trusted communication channels. In addition, if the domain is successfully authenticated, it can lend more legitimacy to fraudulent requests made to businesses that process sensitive customer data.
Why Could High-Net-Worth Users Face Greater Risks?
At this point, the number of impacted accounts seems small, ZachXBT said. He added, however, that the attack could have been aimed at high-net-worth Revolut users.
According to several affected users, they were officially informed about the security incident via emails sent by Revolut. These alerts are used to alert customers that the company has identified the affected customers and begun to notify them directly.
International Cyber Digest reported similar details about the alleged data exposure. The report says that customers could have had copies of their passports, verification selfies and transaction records released.
‼️ BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor.
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later… pic.twitter.com/QFlIlUFpxH
— International Cyber Digest (@IntCyberDigest) September 12, 2026
The report also noted that Revolut notified the relevant government authority of a mailbox that was not theirs. In addition, the company reportedly sealed the mailbox and started to inform the regulators of the incident.
However, several important details remain unclear. Revolut has reportedly not been able to determine the name of the government agency involved or how attackers accessed its mailbox.
Revolut Data Leak Raises Privacy and Security Concerns
The company has also reportedly not revealed the number of customers affected. So, the scope of the alleged Revolut data leak is still unknown.
The leaked data may pose significant privacy and security issues for those who are affected. Specifically, criminals may find it useful to have identity documents, home addresses, and financial histories.
Furthermore, exposed Bitcoin transaction records could help attackers connect real-world identities with blockchain activity. This may raise the targeting risk for users who have significant digital assets.
Those who have been officially notified should take the time to read the information provided by Revolut. They should also be wary of unsolicited messages, account requests and suspicious communications.
The incident is reportedly being investigated and regulatory notifications are reportedly underway. Additional information might be able to shed light on the extent of the users affected, the attack technique and the extent of the information that was exposed.




Be the first to comment