Revolut Says KYC and Bitcoin Transaction Data Exposed After Fake Government Request

Revolut Says KYC and Bitcoin Transaction Data Exposed After Fake Government Request

Revolut said on September 13 that sensitive information belonging to a limited number of customers was disclosed after an unauthorized party used an email account on a legitimate government-agency domain to send fraudulent data requests. The company said it had notified affected customers, regulators and law enforcement, according to The Block.

Fraudulent government-domain request triggered the disclosure

Revolut said the request appeared authentic because it came from an unauthorized mailbox created within an official government authority’s domain infrastructure and carried genuine domain-authentication credentials. The company later determined that the sender’s requests were fraudulent. Revolut said it blocked the address after identifying the issue and notified affected parties.

Exposed records included KYC files and Bitcoin transaction histories

The potentially exposed material included identity documents, verification selfies, addresses, IBANs, account statements, withdrawal records and full transaction histories, including Bitcoin transactions, according to a Revolut customer notice reproduced by Mark Karpelès on X.

The disclosure therefore potentially combined know-your-customer records with information on customers’ account activity. Revolut’s notice described the information as potentially exposed; it did not publicly specify which categories applied to each affected customer.

Scale and agency remain undisclosed

As of September 12, Revolut had not published the exact number of affected customers, identified the government agency whose domain infrastructure was involved, or provided a detailed public timeline for the disclosure, The Block reported.

Revolut said its systems and customer funds were unaffected. In its public account, the company characterised the incident as a fraudulent disclosure request rather than an intrusion into its systems, while providing no further detail on the agency or the scale of the customer-data exposure.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Related Stories