Briefly
- Revolut disclosed delicate buyer information—together with passport copies, verification selfies and full Bitcoin transaction histories—after fulfilling a fraudulent request despatched from a authorities company’s reliable e-mail area.
- A Revolut spokesperson confirmed it was “a classy exterior impersonation rip-off,” stated a “restricted” variety of clients had been affected, and acknowledged methods and funds had been unaffected, however declined to present numbers or title the company.
- ZachXBT stated the breach appeared to focus on high-net-worth customers, elevating “wrench assault” considerations amid a wave of comparable leaks.
Fintech big Revolut handed delicate buyer information, together with passport copies and full Bitcoin transaction histories, to a malicious actor after falling for a fraudulent request disguised as a reliable authorities inquiry.
In keeping with a buyer notification circulated by crypto investigator ZachXBT, Revolut obtained a request for buyer info that appeared to return from a authorities company, despatched from an unauthorized e-mail account utilizing the company’s official area.

As a result of the message carried legitimate area authentication credentials, Revolut fulfilled it within the perception it was real.
The uncovered information was in depth. Per the discover, it spanned id particulars corresponding to full title, date of start and occupation; contact info together with postal deal with, e-mail and telephone quantity; and doc and verification information, together with a duplicate of the sufferer’s passport or driver’s license and the selfie supplied for verification.
Most alarming for crypto holders, the monetary information included account statements with IBAN and pockets reference numbers, withdrawal information and full transaction historical past, together with Bitcoin. Revolut stated no biometric facial telemetry information was concerned.
A Revolut spokesperson confirmed the breach to TechCrunch, describing it as “a classy exterior impersonation rip-off the place an unauthorised third occasion utilised a reliable authorities company area e-mail to submit fraudulent requests for info.”
The corporate stated a “restricted” variety of clients had been affected, that it had blocked the e-mail deal with and alerted the company, legislation enforcement and regulators, and that its methods and buyer funds had been unaffected. Revolut declined to say how many individuals had been hit or which company was impersonated.
ZachXBT stated the incident appeared to focus on high-net-worth customers, a priority given the surge in violent “wrench assaults” towards recognized crypto holders. The leak drew sharp criticism, with a number of customers on social media arguing the episode exhibits know-your-customer guidelines have created threat with out significant profit.
The breach lands amid a tough stretch for companies holding crypto customers’ private information. {Hardware} pockets maker Trezor just lately noticed a support-vendor breach widen to reveal tens of hundreds extra clients, whereas X appeared to undergo an information breach of its personal that flooded customers with password resets.
Revolut, which launched its euro-pegged EURR stablecoin this 12 months, is at the moment weighing an IPO.
Every day Debrief Publication
Begin each day with the highest information tales proper now, plus unique options, a podcast, movies and extra.
