NewsCryptoRevolut Reportedly Exposed User Data After Fraudulent Government Request

Revolut Reportedly Exposed User Data After Fraudulent Government Request

Author: The Market Periodical·

Key Takeaways

  • Revolut disclosed personal and financial customer data—including identity documents, home addresses, IBANs, and full transaction histories—after responding to a fraudulent request made to appear as though it came from a government agency.
  • On-chain investigator ZachXBT revealed the incident on Sept. 12, noting that the request used an official agency email domain and passed domain-authentication checks, and that the breach may have targeted high-net-worth users.
  • Revolut, which recently received conditional approval for a US bank charter from the Office of the Comptroller of the Currency, told affected users their accounts remained secure but has not yet released a public statement.
  • Aave Chan Initiative founder Marc Zeller confirmed he was affected, saying Revolut threatened to close his account within 20 days, and criticized KYC requirements for putting customers at risk.
  • CertiK recorded 52 verified wrench attacks in the first half of 2026 with financial exposure of $124 million, up from $10.5 million a year earlier, and identified major data breaches as a factor behind attacks concentrated in France.
Revolut Reportedly Exposed User Data After Fraudulent Government Request

Revolut appears to have disclosed sensitive customer information after responding to a fraudulent request that was made to look as though it came from a legitimate government agency.

On-chain investigator ZachXBT disclosed the incident on Sept. 12. According to his account, the request used the agency’s official email domain and passed domain-authentication checks. Revolut later determined that the communication was unauthorized.

The number of affected customers remains unclear. ZachXBT said the incident appeared limited in scale and may have targeted high-net-worth users. The information potentially exposed included identity documents, home addresses, phone numbers and financial records.

Revolut Disclosed Addresses, Identity Documents and Financial Data

An email sent by Revolut to affected users reportedly said that sensitive and personally identifiable information had been disclosed. The data included customers’ full names, dates of birth, occupations, passport and/or driver’s-license details, verification selfies, email addresses and postal addresses.

The email also stated that Revolut’s response included financial information such as account statements, International Bank Account Numbers (IBANs), withdrawal records and complete transaction histories, including Bitcoin transactions.

Revolut, a neobank that recently received conditional approval for a bank charter from the US Office of the Comptroller of the Currency (OCC), said in the email that users’ accounts remained secure. The company has not yet released a public statement about the incident. A further company statement would be expected to clarify the incident’s scope and the measures taken in response, but those details have not been publicly provided in the information available here.

Affected Users Raise KYC and Physical-Security Concerns

Some affected users have since spoken publicly. Crypto entrepreneur and Aave Chan Initiative founder Marc Zeller confirmed that he was among those affected. He said Revolut had initially emailed him requesting several pieces of personal information and threatening to close his account within 20 days. Zeller now believes the fintech company was acting on the fraudulent government request at the time.

Zeller criticized know-your-customer (KYC) requirements, saying they “hasn’t produced meaningful upside and has put many in harm’s way.”

The exposure could increase affected customers’ risk of phishing and other targeted scams. The disclosure of home addresses also raises concerns about so-called wrench attacks, in which criminals physically target crypto users to steal their assets.

According to CertiK, there were 52 verified wrench attacks during the first half of 2026, including 33 in France. French authorities reported a higher figure. French Interior Minister Laurent Nuñez said there were 77 crypto-linked kidnapping and extortion cases during the first half of the year.

CertiK said the financial exposure from those attacks reached $124 million, up from $10.5 million during the first half of 2025. The firm identified major data breaches as one factor behind the high concentration of attacks in France.

Sources: ZachXBT investigation, Marc Zeller on X, CertiK report, The Market Periodical.