LIVE
Bitcoin $72-73K: ETF Realized Price and Coinbase PremiumConsensys Split: MetaMask Goes Its Own WayMexican Musician, Family Reportedly Killed Over Bitcoin WalletSecret Service Freezes $52.8M in Crypto Tied to XinbiClarity Act Lobbying: Crypto, Banks Target Senators' Home States1inch Routes Over $800B as Co-Founder Flags DeFi Profit HurdleMalone Lam Pleads Guilty in $245 Million Bitcoin TheftScam Center Strike Force Restrains $52M in Crypto in One DayDee Goens Replaces Jacob Horne as Zora CEORipple's Alderoty Urges Crypto Holders' Input on Clarity ActBitcoin $72-73K: ETF Realized Price and Coinbase PremiumConsensys Split: MetaMask Goes Its Own WayMexican Musician, Family Reportedly Killed Over Bitcoin WalletSecret Service Freezes $52.8M in Crypto Tied to XinbiClarity Act Lobbying: Crypto, Banks Target Senators' Home States1inch Routes Over $800B as Co-Founder Flags DeFi Profit HurdleMalone Lam Pleads Guilty in $245 Million Bitcoin TheftScam Center Strike Force Restrains $52M in Crypto in One DayDee Goens Replaces Jacob Horne as Zora CEORipple's Alderoty Urges Crypto Holders' Input on Clarity Act
Homepage/News/Revolut Phishing Attack Exposes Sensitive Customer Data
NEWS

Revolut Phishing Attack Exposes Sensitive Customer Data

·3 MIN READ·
MakeThe CC Presspreferred onGoogle

Revolut customers had sensitive identity and financial records exposed after fraudsters posed as a government body and tricked the fintech into handing over data, according to a single incident report. The Revolut phishing attack reportedly swept in identity documents, verification selfies, IBANs and even Bitcoin-related transaction activity.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
3Key sections mapped in this report
0Internal references connected to related coverage
5External source domains cited in the article
3 minEstimated time to read the full report

The details come from Crypto Briefing, which reports that an impersonated government data request caused the disclosure of customer identity and financial records. The outlet says Revolut characterized the event as an external impersonation scam, not a breach of its internal systems. For related coverage, see Revolut EURR Stablecoin Launch: What to Know.

No original customer notification, regulatory notice or forensic report has been independently obtained. Every incident detail here traces back to that one report, so treat it as attributed reporting rather than confirmed fact. For related coverage, see Roundhill, Teucrium Shift XRP ETF Dates to October 11.

What is known about the Revolut phishing attack

According to unconfirmed reports, the attackers sent a fraudulent request dressed up as a legitimate government demand for data. Revolut then disclosed the information before the request was flagged as fake. For related coverage, see Hey Wallet Sunsets Products, Impacting Solana Users.

The report dates the start of customer notifications to September 11, 2026. The breach date itself, the impersonated agency and the original email headers were not disclosed, so it is not clear when the actual disclosure happened. For related coverage, see CFTC Probes Polymarket Trades: Biden Pardons, Iran, Google.

This is not Revolut’s first reported brush with a fake-government-request scenario. Earlier coverage described a similar Revolut data leak involving passports and Bitcoin records, and the overlap between the two accounts has not been fully resolved.

What the exposure means for Revolut customers

Crypto Briefing lists the exposed data as identity documents, verification selfies, names, dates of birth, contact information, IBANs, withdrawal histories and Bitcoin-related transaction activity. That is a rich haul for anyone building a targeted fraud campaign.

The exact number of affected customers has not been established. The report describes the group as limited without giving a count, and says systems and customer funds were unaffected, though those are reported assurances, not independently audited findings.

Exposure is not the same as account compromise. According to unconfirmed reports, no passwords, PINs, private keys or customer funds were taken. Data leaks like this typically fuel follow-on phishing rather than direct theft, but that is a potential risk here, not a documented outcome of this incident.

The Bitcoin angle is why the crypto world is watching. Bitcoin traded at $77,152 at retrieval time, but there is no established link between that price and this incident.

Precautions Revolut customers can take

The clearest defense is Revolut’s own general fraud advice. The company’s guidance identifies impersonation of tax officials, police or Revolut itself as a known scam pattern, and tells people to contact the supposed organization through its official contact details instead of sharing information under pressure.

As general practice, open the Revolut app directly to check any message rather than following links in unsolicited emails or texts. Never share passwords or one-time security codes with anyone who contacts you first.

Review recent account activity and report anything unfamiliar through official support channels. This is standard precaution, not remediation advice attributed to Revolut, which has not published incident-specific instructions that could be verified here.

One technical footnote matters. Even if a fraudulent email passes domain authentication checks like SPF, DKIM and DMARC, that proves nothing about legitimacy; the DMARC specification explicitly states that authenticated email should not receive elevated delivery privilege. A message that looks technically valid can still be a scam.

So the real question hangs over the notification list: how many customers are about to find their passports and payment histories in the wrong hands, and who exactly waved the fake request through?

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: cryptobriefing.com
  • External Source - Referenced domain: theccpress.com
  • External Source - Referenced domain: coingecko.com
  • External Source - Referenced domain: revolut.com
  • Byline - Reported by Felix van Dijk
  • Coverage Desk - Primary editorial category: News