Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request
The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.
Revolut provided customer files to an individual who posed as a government official. The imposter used a legitimate government email domain, which led Revolut staff to treat the request as genuine. As a result, the company handed over sensitive information, including passport or driving license copies, selfies used for identity checks, full names, dates of birth, occupations, home addresses, emails, and phone numbers.
The leaked data also included account statements with IBANs, opening dates, withdrawals, and full payment trails, including Bitcoin transactions. According to Revolut, the breach did not involve a hack of their systems, and no customer funds were lost. The company shut down the unauthorized mailbox after realizing it was fraudulent.
The incident was made public by crypto researcher ZachXBT, who issued an alert stating that Revolut appeared to have mistaken a fraudulent government information request for a legitimate one. The company reportedly warned affected customers and investigators.
Brief written by urgent.news from Decrypt, Euro Weekly News, CoinDesk — 3 reports on this story. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Revolut sends out passports and Bitcoin records to a fake email. What to do now euroweeklynews.com
- Bitcoin activity, passports exposed after Revolut falls for fake government request coindesk.com
- Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov’t domain theblock.co