• Revolut disclosed customer data, including Bitcoin (BTC) trading histories, via a fraudulent government request on September 12.
• Exposed data may include KYC documents, facial-verification selfies, IBANs, withdrawal records and complete transaction histories.
• Hackers publicly leaked data of tennis player Alexander Shevchenko and Gamdom CEO Felix Römer.
Revolut's September 12 Customer Notice
British fintech Revolut has confirmed to affected customers that it handed over personal data — including complete Bitcoin (BTC) trading histories — in response to a fraudulent information request impersonating a government agency. The disclosure surfaced on September 12, when copies of the company's customer notification began circulating online. According to that notice, the fraudulent email was sent from an unauthorized mailbox created inside a genuine government agency's official domain and carried valid domain authentication, which led Revolut's compliance team to treat it as a legitimate law-enforcement demand. The data that may have been handed over spans the full KYC file: name, date of birth, occupation, address, email address and phone number, together with copies of passports or driver's licenses and the facial-verification selfies captured at onboarding. Financial records can include IBANs, account status, account opening dates, wallet reference numbers, withdrawal records and the entire transaction history, covering every Bitcoin purchase and sale executed on the platform. Biometric facial-feature data was not involved and was not breached, the company said. On-chain investigator ZachXBT, who reviewed the notification, judged the scale likely limited but observed that wealthy customers — effectively high-net-worth crypto whales — appear to have been the targets. Mark Karpelès, former Mt. Gox CEO, said he was affected and published the notice in a post on X.
Hackers Leak Shevchenko and Römer Records
The affair has since entered a more aggressive second phase. Security monitoring group International Cyber Digest reported on X that the attackers have stopped waiting for a payout and begun publishing the stolen material directly, releasing selfies and identity-document copies of high-profile customers, among them tennis player Alexander Shevchenko and Felix Römer, chief executive of online crypto casino Gamdom. In a Telegram message quoted alongside that post, the threat actors stated they would release more data every day until Revolut “pays for leaking customer data.” The escalation carries particular weight for crypto users because Revolut is one of the few consumer apps that unifies fiat banking, equities and crypto trading in a single account: a leak of this kind does not merely expose identities, it hands attackers a complete map of each customer's digital-asset activity — what was bought, in what size, and when. With KYC selfies and ID documents already in the open, the identity-theft surface now extends well beyond Revolut itself, to loan applications, account openings at other venues and precisely targeted phishing. Anyone comparing venues through our Best Crypto Exchanges guide should weigh how each platform verifies law-enforcement requests before surrendering records.
Verified Domain, Undisclosed Agency
Several load-bearing details remain undisclosed. Revolut has not named the agency whose domain was abused, explained how an unauthorized mailbox obtained valid credentials inside official infrastructure, or specified how many customers were affected, describing the number only as a “limited number.” The company maintains that its systems and customer funds were untouched — login credentials, card numbers, private keys and balances were not part of the exposed set — and says it has since blocked the fraudulent mailbox, contacted the agency directly to flag the rogue account, and notified data-protection and financial regulators while applying precautionary protections to the affected accounts. The episode is also separate from July's claim, circulated on a cybercrime forum, that 75 million Revolut customer records had leaked; the company rejected that assertion at the time, saying it found no sign of intrusion and that the sample identifiers did not match real accounts. No regulator has issued formal public comment so far. The timeline matters: the company confirmed the fraudulent disclosure to customers on September 12, and the hackers' first public dumps followed across the weekend of September 13, suggesting the ransom deadline is already active.
Compliance Inboxes as Attack Surface
In our reading, the three threads — the fraudulent request, the ransom-driven leak and the still-unidentified agency — expose one structural weakness: fintech platforms that hold KYC files and long-term HODL-style crypto positions in the same account have become one-stop targets for law-enforcement-request impersonation. As our Bitcoin security coverage has documented from the recent Symbiosis bridge hack onward, the attack surface now stretches from smart contracts to a compliance officer's inbox. The primary record here is the customer notice Karpelès published; until the agency is named, both Revolut's verification workflow and the government's own mailbox security remain unverified.
