BC.GAME promotional banner

WIN

Subscribe

Revolut Hackers Leak Customer IDs After Fake Government Requests
3–5 minutes
Fact Checked by Mazel Ventura

Last Updated:

September 14, 2026

Revolut logo on a smartphone with a hooded hacker and floating identity documents in a dark blue and red cybercrime scene.

Revolut Hackers Leak Customer IDs After Fake Government Requests

Revolut logo on a smartphone with a hooded hacker and floating identity documents in a dark blue and red cybercrime scene.

Hackers who obtained sensitive Revolut customer information through fraudulent government requests have reportedly started publishing identity documents and selfies online, escalating a data breach that the fintech confirmed days ago.

According to a post on X by International Cyber Digest, the attackers are also threatening to release more customer information each day unless Revolut pays. The reported leaked material includes identity documents and verification selfies belonging to some customers. The exact number of people affected and the full scope of the published data remain unclear.

Hackers Used a Legitimate Government Domain

The incident began when an unauthorized party sent fraudulent requests for customer information from an email account operating under the domain of a legitimate government agency.

Revolut initially treated the requests as genuine and disclosed customer information to the unauthorized recipient. The company later identified the activity as a “sophisticated external impersonation scam” and blocked the email address. Revolut said its systems and customer funds were not affected.

The company notified the affected customers, the government agency whose domain was used, law enforcement, data protection authorities, and financial regulators.

Revolut has described the number of affected customers as limited but has not released an exact figure or identified the government agency involved.

Identity Documents and Bitcoin Records May Be Exposed

The customer notification reviewed by multiple outlets shows that the incident went beyond basic contact information. Potentially exposed information included customer names, dates of birth, occupations, postal addresses, email addresses and phone numbers.

Copies of passports and driver’s licenses, verification selfies, account statements and complete transaction histories may also have been disclosed.

The notification also indicated that IBANs, withdrawal records and full transaction histories, including Bitcoin transactions, could have been shared with the unauthorized party.

This gives the incident a direct cryptocurrency angle because transaction histories could reveal a customer’s digital-asset activity in addition to their identity information.

Former Mt. Gox CEO Mark Karpelès said he was among the affected customers and publicly shared the notification he received.

Attackers Reportedly Begin Publishing Customer Data

The breach has now reportedly moved into an extortion phase. Attackers have reportedly begun publishing sensitive Revolut customer information online, including identity documents and verification selfies. The attackers also threatened to release additional customer data each day unless Revolut pays, according to The Block.

The amount of money demanded has not been disclosed. Revolut has not publicly confirmed the ransom demand or the identities of the customers whose information was reportedly published.

The reported publication of customer data adds a new layer to the breach, which Revolut confirmed after unauthorized parties obtained information through fraudulent government requests.

Why the Breach Is Different From a Direct System Hack

Revolut has not said that attackers broke into its core banking systems or directly accessed customer accounts.

Instead, the incident involved the company responding to what appeared to be legitimate government information requests. The requests came from an email account within a real government agency’s domain, allowing attackers to exploit trust in the request’s source.

The case therefore centers on social engineering and impersonation rather than a disclosed compromise of Revolut’s core systems. This kind of impersonation tactic is similar to the pressure and trust exploits seen in common P2P scams, where attackers rely on a convincing setup rather than a technical break-in. 

Revolut said it blocked the fraudulent email address after discovering the activity and introduced precautionary measures for affected customers. The company has also involved authorities and regulators in the investigation.

Revolut Has Not Disclosed the Full Scope

Several important details remain unknown. Revolut has not said exactly how many customers were affected, which government agency’s domain was involved, how much information was disclosed for each customer, or whether the same fraudulent account was used to target other financial institutions.

On-chain investigator ZachXBT posted Revolut’s email to affected customers, providing further details about the information that may have been exposed.

The reported publication of identity documents raises another concern. A combination of passports, driver’s licenses, selfies, addresses, and financial records could provide attackers with material for identity theft and highly convincing phishing attempts.

What Comes Next

The immediate focus is likely to be on identifying the attackers, determining exactly which customer records were obtained, and preventing additional information from being released.

Revolut has already notified law enforcement, regulators and the affected government agency. The company has also blocked the email address used in the fraudulent requests.

The reported release of customer documents adds pressure to the investigation because the incident has moved beyond unauthorized disclosure into a possible extortion campaign.

What This Means for You: Revolut customers who received a breach notification should treat unexpected messages involving their account, identity, or cryptocurrency activity with extra caution. The reported exposure does not mean customer funds or Revolut’s core systems were compromised, but leaked identity and transaction information could make targeted scams more convincing.

Join our growing community

David Constantino

Author

David is a crypto enthusiast, airdrop farmer, and blog writer with a focus on discovering and analyzing new token launches and blockchain projects. He explores the latest trends, shares actionable insights, and guides readers through opportunities in the fast-paced world of digital assets.