Revolut Exposed Customer Passports and Crypto Data After Falling for Fake Government Request
Revolut has told affected customers that their personal and financial information may have been disclosed after the company responded to a fraudulent request that appeared to come from a real government agency. The request was sent from an unauthorised mailbox within the agency's genuine domain and used valid authentication credentials, which helped it pass as legitimate.
The exposed data reportedly included passport or driver's licence copies, identity verification selfies, names, dates of birth, home addresses, phone numbers, bank account details and full transaction histories, including Bitcoin activity. Revolut has not disclosed the number of affected customers or named the agency involved. After later determining the request was fraudulent, Revolut blocked the mailbox and began notifying regulators and customers.
Because Bitcoin transactions are recorded on a public blockchain, linking a verified identity to specific wallet activity could allow attackers to trace a customer's wider financial footprint beyond what was directly disclosed. Commentators have noted this incident highlights the risk created when financial firms hold extensive identity and transaction records to meet compliance obligations, since those same records become high-value targets if verification processes are tricked.