Revolut Shared Customer Records After Accepting Fake Government Request
Key Takeaways
- •Revolut treated a fraudulent government-style request as legitimate and disclosed customer records.
- •The available evidence does not establish when or where the incident occurred, what records were shared, or how many customers were affected.
- •The specific verification failure and submission channel remain unknown.
- •The FBI has warned companies about criminals using fake emergency data requests while impersonating officials.
- •No confirmed customer notification, company response or remediation plan is included in the available evidence.

Fintech company Revolut handed over customer records after accepting a government request that later proved to be fake, according to reporting on the incident. The case illustrates how criminals can impersonate an official agency and persuade a company to release sensitive personal data.
What happened
Revolut disclosed customer records after treating a fraudulent request as legitimate. According to reporting from CryptoSlate, the request was designed to appear as though it had been issued by a government body.
The available evidence does not confirm the exact date of the incident or the jurisdiction involved. It also does not specify every type of record that was disclosed. The number of affected customers and the full scope of the impact remain unconfirmed.
Revolut has expanded quickly in recent years, including through its move to roll out a euro stablecoin across the European Union. That growth makes the protection of customer information a significant concern for a large user base.
Verification questions remain
The central issue is how the request was verified. Although the request was fraudulent, it was accepted, indicating a gap in the process used to authenticate such demands. The impersonation of law enforcement or government agencies to obtain user data is a known tactic.
The U.S. Federal Bureau of Investigation has warned about fraudulent “emergency data requests” sent to companies by criminals posing as officials. Its public service announcement is available at ic3.gov.
The available evidence does not explain which channel was used to submit the fake request. It also does not describe the checks Revolut conducted before releasing the records. As a result, the specific process failure has not been confirmed.
Customer impact and company response are unverified
The evidence indicates that records were handed over, but it does not provide a verified count of affected customers. The precise mix of documents disclosed has also not been established.
No confirmed company statement, customer notification, or remediation plan appears in the available evidence. The extent of any harm to customers therefore cannot yet be stated with confidence.
For Revolut users, the practical response is to remain alert for unusual account activity and phishing attempts. Leaked identity documents can be reused in follow-on scams. Revolut is also continuing its banking ambitions, including conditional approval toward a U.S. bank charter in 2027, increasing the importance of safeguards for its customer records.
This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Readers should conduct their own research before making decisions.