
Revolut confirmed on September 12 that it disclosed sensitive customer information to an unauthorized third party after fraudulent requests arrived from a legitimate government-agency email domain. The company says its systems and customer funds were unaffected. It has not disclosed how many people were involved or whether customers in the United States were among them.
The crypto-specific concern comes from the information reportedly included in notices to affected customers. Alongside identity and contact records, those notices described transaction histories that included Bitcoin activity, according to reporting that reviewed or cited the customer communication.
What is confirmed—and what is not
Confirmed: Revolut disclosed customer data after deceptive requests from an authentic agency domain and says funds and its systems were unaffected. Not disclosed: the agency, the exact customer count, affected markets, or a complete record-by-record inventory for every customer.
A trusted domain carried an unauthorized request
A Revolut spokesperson confirmed the incident to Reuters, describing fraudulent information requests sent from a legitimate government-agency email domain. After detecting the deception, Revolut said it blocked the address and alerted the agency, law enforcement, data-protection authorities and financial regulators.
This distinction matters. The company has not described an attacker breaking into a customer account or draining funds. The disclosed mechanism was an impersonation attack against the process used to authorize official information requests. An authentic-looking channel persuaded the company to release data to someone who was not entitled to receive it.
TechCrunch reported that a notification it reviewed listed birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver’s licenses. The notice said verification selfies, account statements and transaction histories may also have been included. Revolut told the outlet that a “limited” number of customers were affected, without providing a number or geographic breakdown.

Why reported Bitcoin histories raise a distinct privacy risk
CoinDesk reported that the customer notice listed withdrawal records and full transaction histories, including Bitcoin activity. Revolut’s public comments reported by Reuters did not separately enumerate Bitcoin records, so that detail should be understood as coming from the affected-customer communication cited by reporters.
Bitcoin transactions are recorded on a public ledger, but a blockchain address does not by itself display a passport name or home address. A financial intermediary’s records can connect an identifiable customer to deposits, withdrawals and wallet references. If identity documents, contact details and Bitcoin history appear in the same unauthorized disclosure, the result can be more revealing than either dataset alone.
That does not mean private keys, passwords or spend authority were exposed. None of the reviewed reports said those credentials were included, and Revolut said customer funds were unaffected. It does mean an unauthorized recipient may have received information useful for identity fraud, tailored phishing or attempts to map a person’s financial activity.
The customer count and U.S. impact remain unknown
Revolut has not named the government agency whose domain was used, disclosed the number of affected customers, or said whether the incident was confined to one country. Without that information, it is not possible to conclude that U.S. customers were affected—or that they were not.
The same caution applies to the reported scope of the files. A notification can list categories that may have been disclosed without establishing that every affected person had every category of data in the package. Claims that all customers lost complete Bitcoin histories would go beyond the available evidence.
The next useful disclosures would include a dated incident timeline, the number and location of affected customers, the authorization controls that failed, the precise data fields released and any findings from regulators or law enforcement.
What affected customers can verify now
Revolut says it contacted affected customers directly. Anyone receiving such a notice should verify it through the Revolut app or an independently sourced support channel rather than following unexpected links. Account alerts, recent statements and credit reports can help surface misuse, while extra caution is warranted for messages that cite accurate personal or transaction details to manufacture trust.
Changing an account password is sensible security hygiene, but it cannot recall identity documents or transaction records already disclosed. Customers should separate two questions: whether account access is secure now, and whether exposed personal information could be abused later.
Quick answers
Were Revolut customer funds stolen?
Revolut says its systems and customer funds were unaffected. The confirmed incident involved unauthorized disclosure of information, not a reported theft from customer balances.
Were Bitcoin records exposed?
Customer notices cited by CoinDesk reportedly included Bitcoin transaction histories and withdrawal records. Revolut’s confirmation reported by Reuters did not publish a separate field-by-field inventory.
How many customers were affected?
Revolut has not disclosed an exact number. It described the affected group as limited in comments reported by TechCrunch.
Investment disclaimer: This article is provided for general information only and does not constitute investment, financial, legal or tax advice. Digital assets are volatile, and all investment decisions and their consequences are your own responsibility.