ZachXBT alleges Revolut disclosed sensitive customer data after spoofed government request
Public reports describe a limited incident involving identity and transaction records, but Revolut has not publicly confirmed the full scope or whether high-net-worth users were targeted.
On-chain investigator ZachXBT has alleged that Revolut disclosed sensitive customer information after treating a fraudulent government data request as legitimate. The Block reports that Revolut described the incident as a sophisticated external impersonation scam and said a limited number of customers were directly notified. A CryptoTimes report also says the request appeared to come from an official domain. Public reporting still does not establish the full scope or final regulatory findings.
The records reportedly include names, contact details, identity-document copies, verification selfies, IBANs, account statements, withdrawal records and transaction histories that may include Bitcoin transfers. The exact number of affected accounts, jurisdictions and categories of data remain unclear in public reporting. Alleged exposure is not confirmed scope: readers should not assume every Revolut customer was affected or that every listed data type was disclosed.
The report says the request was sent through a mailbox that appeared to belong to a government agency and passed ordinary email-authentication checks. That could explain why a request looked credible without proving that Revolut's review process was legally or operationally adequate. Public evidence currently consists of investigator posts, customer notifications and screenshots described by secondary reporting.
The high-net-worth targeting theory also remains unproven. ZachXBT reportedly said the affected group appeared limited and may have included wealthier customers because the exposed records could reveal balances, banking relationships and crypto activity. That is an investigative hypothesis, not evidence that the incident was designed around a verified wealth list.
Why the data could create follow-on risk
A leak combining identity documents with account statements and Bitcoin transfers can create risks beyond ordinary phishing. Criminals may use the records to tailor impersonation calls, attempt account recovery, identify likely balances or threaten people who appear to hold valuable assets. The information can also be reused across jurisdictions and services long after a company closes the original request.
Revolut's public fraud guidance tells customers to access the app directly, avoid unexpected links and remember that legitimate organizations will not ask users to move money to another account. Those controls are useful for customers who receive suspicious messages, but they do not independently confirm the alleged disclosure or explain how the company validated the request.
The next evidence is a direct incident notice from Revolut or a regulator. That notice should clarify the affected entity, dates, data categories, customer count, containment steps and whether biometric material was included. Customers who received a notification should preserve it, contact Revolut through the official app and consider local data-protection or fraud-reporting channels.
This article reports an allegation and public responses, not a final finding of negligence or unlawful processing. Readers should not publish exposed documents, attempt to identify victims or treat leaked transaction data as a trading signal. Digital-asset users should also review account security, phishing resistance and personal safety plans without disclosing seed phrases or private keys.