
Fintech company Revolut confirmed the exposure of confidential data of a limited number of clients after unknown individuals used a legitimate email domain of a government agency to send fraudulent requests. The incident was reported by on-chain researcher ZachXBT, noting that the compromised information could include document copies, bank statements, and a complete transaction history, including Bitcoin transfers.
Revolut was unable to recognize the fraudulent request as fake because it came from a legitimate government agency domain. The data that could have been exposed includes: full name, date of birth, and occupation; home address, email, and phone number; copies of passport and/or driver's license; selfies for verification; bank statements, including IBAN, account status, opening date, and wallet number; withdrawal records; complete transaction history, particularly Bitcoin operations. Revolut clarified that biometric data obtained from facial analysis was not compromised. According to ZachXBT, the attack could have been targeted at wealthy clients, and several affected individuals have already received official notifications. The exact number of affected individuals, as well as the country of the incident and the specific government agency whose domain was used, were not disclosed by the company.
The incident sparked a wave of criticism on social media platform X. Aave co-founder Marc Zeller stated that he learned about the exposure of his data, calling it a reminder that KYC has not provided significant benefits while creating additional risks for users. User Nikhil Foster confirmed receiving a notification and noted that the leaks included a passport copy, selfie, and complete transaction history, ironically remarking that 'facial biometric data' was supposedly not affected. Charles Reed stated that he learned about the breach of his data from this story. Financial expert Austin Campbell emphasized that banks and regulators are 'completely unprepared' for modern forms of fraud. Mert Mumtaz, co-founder and CEO of Helius, noted that such leaks could lead to home robberies and suggested conducting KYC based on zero-disclosure proofs.
A representative of Revolut confirmed the incident to TechCrunch, stating that the company identified a 'sophisticated external impersonation scheme.' According to him, Revolut blocked the used address and notified the government agency, law enforcement, and regulators. 'Revolut's systems and client funds were not affected,' he added.





