Revolut has disclosed a data-security incident in which sensitive customer information was released after the financial technology company received a fraudulent request that appeared to originate from a legitimate government agency.

The incident reportedly exposed highly sensitive Know Your Customer (KYC) documentation and detailed financial records belonging to a limited number of users, including passport or driver’s license copies, identity-verification selfies, account statements, and complete transaction histories that included Bitcoin-related activity.

According to Revolut’s explanation, the disclosure did not result from a compromise of its core systems, mobile application, or customer accounts. Instead, the company said it was targeted through a sophisticated impersonation operation involving an unauthorized email account operating under an official government agency’s email domain.

Because the message carried valid domain-authentication credentials, Revolut believed it was handling an authentic legal or government information request and fulfilled it.

The response provided extensive information. It included customers’ full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers.

The exposed document and verification data reportedly included copies of identity documents, such as passports and driving licenses, along with facial-verification images submitted during onboarding.

Revolut highlighted that biometric facial telemetry was not involved or compromised, although the loss of document scans and verification selfies could still create serious identity-theft and impersonation risks for affected individuals.

Financial data included account statements containing IBANs, account status information, account-opening dates, wallet reference numbers, withdrawal records, and full transaction histories.

The inclusion of cryptocurrency transaction records, including Bitcoin activity, is particularly sensitive because it could help criminals profile victims’ wealth, trading behavior, wallet usage, and potential exposure to targeted scams.

Revolut described the event as a sophisticated social-engineering attack rather than a breach of its internal infrastructure. The company said it moved quickly to block the unauthorized email source, notify relevant authorities, and contact affected customers. It also maintained that customer funds remained safe and that its systems were not compromised.

However, the incident has triggered renewed concern over the security implications of mandatory KYC data collection across banks, fintech platforms, and cryptocurrency services. On-chain investigator ZachXBT and other cryptocurrency community figures highlighted claims that the operation targeted high-net-worth users, a group that faces elevated risks of phishing, SIM-swapping, extortion, physical threats, and highly tailored cryptocurrency theft attempts.

For impacted Revolut customers, the combination of identity documents, contact details, account information, and transaction history could provide attackers with the material needed to construct convincing social-engineering lures. Fraudsters may impersonate Revolut support staff, law-enforcement agencies, exchanges, or tax authorities while using personal information to make messages appear legitimate.

The case also demonstrates how trusted email domains can be abused when an attacker gains access to, or misuses, a legitimate organization’s mail infrastructure.

Even properly authenticated email can be malicious when the sender account itself is unauthorized. The incident underscores the need for organizations handling sensitive customer records to independently validate high-risk information requests through out-of-band channels, rather than relying solely on domain authentication or sender identity.