ZachXBT Exposes Revolut Verification Breach Triggered by Fake Government Request

Changelly
Blockonomics


Breach notifications from fintech companies like Revolut follow a tired script, a vague reference to “unauthorized access,” a promise that passwords are safe, and a suggestion to change your PIN just in case.

What’s landed on users this week reads nothing like that.

According to an alert shared by on-chain investigator ZachXBT through his Telegram channel, a subset of Revolut customers had their passports, verification selfies, full transaction histories and home addresses exposed after the company reportedly failed to catch a fraudulent government request. That’s not a routine phishing scam or a leaked password list, that’s the kind of exposure that follows you around for years, and I think it deserves a closer look than a one-line security notice usually gets.

What Reportedly Went Wrong Inside Revolut’s Verification Process

The mechanism here is what makes this stand out to me. Financial institutions like Revolut receive legitimate government requests for user data constantly, law enforcement inquiries, court orders, regulatory demands, and they’re built to comply with those when properly verified. What ZachXBT’s alert describes instead is a fraudulent request that slipped through that verification layer, meaning someone impersonated a government authority convincingly enough to get Revolut to hand over customer files without catching the deception.

bybit

ZachXBT Exposes Revolut Verification Breach Triggered by Fake Government Request

I find that distinction important, because it means this wasn’t a hacker breaking through a firewall at 2 a.m., it was someone exploiting the trust built into a compliance process that’s supposed to be one of the more carefully guarded parts of any regulated fintech.

The Data That Was Reportedly Exposed

The scope of what reportedly went out the door is what makes this feel different from a typical fintech incident. Affected users had copies of their passports and driver’s licences exposed, along with the verification selfie taken alongside them, the exact combination identity thieves need to convincingly impersonate someone.

On top of that, ZachXBT’s post describes account statements, IBAN details, withdrawal records and full transaction history, including Bitcoin activity, being exposed as well, alongside full name, date of birth, occupation, home address, email and phone number. I keep coming back to how complete that picture is. Individually, a leaked email address or an old address on file is a minor annoyance. Put all of it together in one dataset, and you’ve handed someone everything they’d need to pass identity checks at another bank, apply for credit in someone’s name, or run a highly convincing impersonation scam.

ZachXBT Exposes Revolut Verification Breach Triggered by Fake Government Request

Why This Looks Targeted At High Net Worth Users

What I find most unsettling about this particular incident is the apparent targeting. ZachXBT’s alert indicates the exposure was likely limited in overall size but appears to have been aimed specifically at high net worth users rather than a broad customer scrape. That’s a meaningfully different threat model than a mass data dump sold for pennies on a forum.

A small, targeted set of wealthy account holders with full financial and identity documentation exposed is exactly the kind of dataset that gets used for spear-phishing, fraudulent wire requests, or direct extortion attempts rather than bulk resale. If I were one of the users affected, I’d be far more worried about a personalized, convincing scam call than a random credential-stuffing attempt.

ZachXBT Exposes Revolut Verification Breach Triggered by Fake Government Request

How Revolut Has Responded So Far

From what ZachXBT’s alert describes, Revolut sent an email notification to affected users yesterday, which suggests the company is at least aware of the incident and treating it seriously enough to reach out directly rather than staying silent. I haven’t seen a broader public statement from Revolut addressing the scope or root cause beyond what ZachXBT surfaced, and I think that gap matters.

Revolut’s own fraud and security guidance, which the company maintains for exactly these kinds of situations, encourages affected users to freeze cards, watch for suspicious contact claiming to be from the company, and report anything unusual immediately, advice that applies here with extra urgency given how complete the exposed profile appears to be for the people affected.

What I’d Watch For If I Were An Affected User

If I held a Revolut account and fit the profile being described here, I wouldn’t just be watching my Revolut balance, I’d be watching everywhere that passport and selfie combination could be reused. That means treating any unexpected verification request, loan application confirmation, or “your identity was used to open an account” notification from an unrelated service as something to investigate immediately rather than dismiss. I’d also be far more suspicious than usual of any call or message claiming to be from Revolut’s support or security team over the coming weeks, since whoever obtained this data now has enough personal detail to make an impersonation attempt sound uncomfortably convincing.

The Bigger Question This Raises For Fintechs

What sticks with me about this incident isn’t really about Revolut specifically, it’s about how much trust every digital bank places in the authenticity of a government request before releasing customer files. That verification step is supposed to be one of the harder walls to get through, and if a fraudulent request can walk past it, the same weakness likely exists at other institutions that haven’t been tested yet. ZachXBT has built a track record of surfacing exactly this kind of incident before it hits mainstream coverage, and I don’t think this is the last time we’ll hear about a “government request” being the attack vector rather than the excuse. I’ll be watching to see whether Revolut, or the wider industry, treats this as the wake-up call it looks like.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on X @nulltxnews



Source link

Blockonomics

Be the first to comment

Leave a Reply

Your email address will not be published.


*