The institution shared personally identifiable information from an unknown number of users after receiving a request from an unauthorized government email account. The shared documents include identity details, ID and verification information, and financial statements, putting affected users at risk.
Revolut Leaks Customer Data to Hackers Posing as State Agency

Key Takeaways
- Revolut leaked user data to hackers posing as a government agency, exposing clients to identity theft risks.
- The leaked data included names, addresses, and ID images, which ZachXBT warned targeted high-net-worth users.
- This breach fuels global backlash against mandatory KYC rules as physical attacks on holders escalate.
Revolut Leaks Customer Information To Unidentified Threat Actors
Revolut, a UK-based neobank, became the latest institution to inadvertently disclose client information to threat actors.
According to an email sent to customers, Revolut, which has a user base of over 70 million customers globally, shared personally identifiable information (PII) with unidentified threat actors who posed as a government agency. The company reported that it delivered this data while it was complying with a request-for-information email that originated from an unauthorized address hosted on a domain.
“The communication carried genuine domain authentication credentials leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request,” it stressed.
Revolut did not disclose the name of the institution allegedly involved. Nonetheless, it did point out that the shared information included key details: names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers, potentially risking the personal security of the customers involved in the leak.
In addition, Revolut also shared documents and verification data, including passport and driver’s licence images with facial verification pictures, which can expose them to ID theft.
Marc Zeller, founder of the now-defunct Aave Chan Initiative, was one of the customers affected by the leak.
“Woke up to all my data leaked by Revolut. Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way,” he posted on social media channels.
Onchain sleuth ZachXBT pointed out that while the incident was likely limited in size, it seems to have been aimed at high-net-worth users, increasing the chances of being targeted for affected customers.
The incident comes amid a global know-your-customer (KYC) backlash after several institutions and crypto companies have also leaked client information to threat actors, risking users’ personal security, as wrench attacks have risen in frequency and ferocity.
















