Revolut disclosed customer identity and Bitcoin records after a fraudulent government request
Revolut's customer notice describes a fraudulent request from a mailbox inside a government domain, with identity documents and transaction records potentially disclosed.

Revolut says it released customer information in response to a fraudulent government request. Its notice, published by recipient Mark Karpelès on 12 September, lists passport or driving-licence copies, verification selfies and financial records, including Bitcoin transactions, among the information potentially disclosed.
How did the request appear legitimate?
According to the notice reproduced by Karpelès, the sender used an unauthorised email account created within an official government authority’s domain. Revolut says the communication carried genuine domain-authentication credentials and was treated as an authentic request.
Email authentication can establish that a message came through a domain’s infrastructure, while the authority of the person making the request still requires a separate check.
Revolut says it subsequently contacted the agency independently, alerted it to the unauthorised account, blocked the address internally and began notifying relevant regulators. It also says it applied protective measures for affected customers.

Which information was involved?
The notice uses conditional wording for the individual records affected. Its categories cover:
| Category | Information listed |
|---|---|
| Identity and contact | Name, birth date, occupation, postal address, email and phone number |
| Verification | Identity-document copy and onboarding selfie |
| Financial activity | Account statements, IBAN, account details, withdrawals and transaction history, including Bitcoin |
Revolut distinguishes the verification photograph from biometric facial telemetry, which it says was excluded. The notice leaves the customer count and the government agency’s identity unspecified.
Bitcoin records connect identity with financial activity
Records linking a named person, a home address and crypto activity can make an impersonation attempt much more convincing. A caller may be able to repeat genuine account details while asking the customer to take an unsafe action.
In a public response, Kraken security executive Nick Percoco described the requests as targeted and warned affected recipients about increased physical-security risk. That is his assessment of the disclosure; possession of the records alone does not establish a subsequent attack.

Verifying a suspicious approach
Revolut’s fraud guidance directs customers to the in-app chat when a call or message appears suspicious. Opening the app independently gives affected customers a direct route to verify the notice and ask which of their records were supplied.


