Revolut Disclosed Data on 680 Customers After Fraudulent Government Requests
Key Takeaways
- •Cybercriminals tricked Revolut into disclosing sensitive information on 680 customers by submitting fraudulent data requests from a genuine government email account, per the Financial Times.
- •The leaked records contained passport details, bank account numbers, home addresses, identity-verification images and Bitcoin activity, and the attackers are threatening to publish the data unless a ransom is paid.
- •Revolut blocked the compromised email account after detecting the fraud and informed both regulators and affected customers.
- •The UK Information Commissioner's Office has launched an investigation into the incident and holds the authority to impose financial penalties for data protection breaches.
- •Former Mt. Gox CEO Mark Karpelès was among the affected customers, underscoring the breadth of the disclosure.

Revolut, the London-headquartered financial technology company, disclosed sensitive information belonging to 680 customers after cybercriminals used a legitimate government email account to submit fraudulent requests for customer data, according to a report by the Financial Times.
The exposed information included passport details, bank account numbers, home addresses, identity-verification images and Bitcoin activity. According to the report, the attackers are now threatening to release the stolen information unless Revolut pays a ransom. News of the incident was also highlighted by @WuBlockchain on X.
Rather than exploiting a conventional technical vulnerability to directly access customer systems, the attackers reportedly used the trusted status of the government account to obtain the information from Revolut, submitting fraudulent data requests that appeared to originate from an official channel. Financial institutions routinely receive and act on official data requests from government agencies, a process that relies on the assumption that instructions arriving through authoritative channels are genuine. Security researchers have previously documented cases in which criminals used compromised government or law-enforcement email accounts to trick companies into handing over user data.
Revolut Blocks Compromised Government Email Account
Revolut said it blocked the email account after identifying the fraudulent activity and notified both regulators and affected customers.
The company is also facing scrutiny from the UK Information Commissioner's Office (ICO), the UK's independent regulator for data protection, which has opened an investigation into the incident. The ICO has the authority to impose financial penalties on organisations found to have breached data protection law. The regulator's involvement could place additional focus on how financial institutions authenticate data requests and protect sensitive customer information when dealing with external authorities.
Among those affected was Mark Karpelès, the former CEO of Bitcoin exchange Mt. Gox — the Tokyo-based platform that collapsed in 2014 after one of the industry's largest hacks — a detail that highlights the breadth of the customer information involved.
Bitcoin Activity Among Exposed Data Raises Security Concerns for Crypto Users
The incident carries particular significance for cryptocurrency users because the compromised information reportedly included Bitcoin activity alongside conventional financial and identity records. Fintech companies hold much of this information because anti-money-laundering rules require them to verify customer identities before providing services.
Combining financial information with passport details, residential addresses and identity-verification images can create additional risks for affected individuals, particularly where attackers attempt to use the material for further fraud or extortion.
The episode also underscores a broader security challenge for financial technology companies: legitimate communication channels can themselves become tools for social engineering when attackers gain access to trusted institutional accounts.
Revolut's response, including blocking the compromised account and notifying regulators and customers, will now be examined alongside the ICO investigation. The key outstanding issue is how the fraudulent requests were authenticated and whether additional safeguards will be required to prevent similar disclosures.
Source: Hokanews