Revolut, a Fintech company, has reportedly disclosed sensitive customer information mistakenly. This information includes complete Bitcoin transaction histories of its high-net users. The company shared the information itself responding to a fraudulent government information request and no hack was involved. Instead, the incident involved a sophisticated impersonation attempt appearing to be a government agency. This incident has been reported by on-chain investigator ZachXBT.

Revolut Data Leak Includes Sensitive Customer Information
According to ZachXBT, the third party behind the request used an email address from the domain of a legitimate government agency. The email request looked so legitimate that it easily passed authentication checks. Revolut reportedly treated the request as genuine and provided detailed customer records. Later, the company found that the request was fraudulent.
The exposed information reportedly includes customers’ full names, contact details, identity documents (passports and driver’s licenses), verification selfies, IBANs, bank statements. Additionally, the information includes Bitcoin withdrawal records and transaction histories too.
For crypto users, the disclosure is particularly significant because the records reportedly include Bitcoin transfers made through Revolut and its crypto trading platform, Revolut X. This could potentially connect verified identities with their on-chain Bitcoin activity. The incident highlights broader concerns surrounding the handling of KYC information by centralized financial and crypto platforms.
ZachXBT said the number of affected accounts appears limited so far as the incident seems to have focused on high-net-worth individuals. Some affected customers have reportedly received notification emails from Revolut regarding the data exposure.
Revolut Says Customer Funds Remain Safe
Revolut has said that its systems and customer funds were not affected by the incident. The company also stated that biometric facial telemetry data was not included in the compromised information.
The fintech firm has blocked the source of the request and notified affected customers and regulators. However, the reported exposure of $BTC transaction histories could create additional risks for affected crypto users. The information has the potential to connect real-world identities with specific on-chain transactions and wallet activity. The combination of identity documents, contact information, and Bitcoin transaction histories may potentially increase the risk of targeted phishing and social engineering attacks.

