A number of Revolut customers reported being told that some of their personal and financial data, including Bitcoin transactions, was disclosed in response to a government request believed to be legitimate.
According to an email text shared by onchain sleuth ZachXBT, the request was sent from an unauthorized email account using the government agency’s official domain and carried valid domain authentication credentials.
The exposed data included customers’ full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers. Identity and verification information, including passport or driver’s license copies and verification selfies, was also listed.
The exposed financial data included account statements, IBANs, withdrawal records and full transaction histories, including Bitcoin activity. The email said biometric facial telemetry data was not shared.
Experts suggested that Revolut may have failed to recognize that the request was fraudulent before sharing customer information.







