Skip to content
Revolut Suspected of Leaking High-Net-Worth Users' Data Due to Phishing Request

Revolut Suspected of Leaking High-Net-Worth Users' Data Due to Phishing Request

Kucoin September 12, 2026

BlockBeats news, on September 12, on-chain detective ZachXBT posted on his personal channel stating that Revolut reportedly leaked some users' personally identifiable information (PII) due to failing to identify a forged request from a government agency.

According to its disclosure, Revolut previously received a request for customer information that appeared to come from a legitimate government agency and was sent using the agency’s official email domain. Due to the email’s valid domain authentication information, Revolut assumed the request was genuine and responded accordingly.

The data potentially involved in this incident may include users’ names, dates of birth, occupations, addresses, email addresses, and phone numbers, as well as copies of passports or driver’s licenses, identity verification selfies, account statements, IBANs, withdrawal records, and complete transaction histories, including Bitcoin transaction records. Revolut stated in its notification to users that no biometric facial telemetry data was compromised.

ZachXBT stated that the current incident may be limited in scope, but the circumstances suggest it primarily targets high-net-worth users. Several Revolut users received notifications regarding this security incident yesterday. Revolut has previously advised users to verify any suspicious messages through in-app customer support and to avoid providing personal or financial information.

Extracted Entities

Attack Types (2)

Companies (1)

MITRE ATT&CK (1)