Revolut Admits to Transmitting Passport Information and Bitcoin Data to Fraudulent Government Address
Revolut has confirmed that attackers impersonating a government agency obtained sensitive customer data including passports, verification photos, and complete Bitcoin transaction records. The incident raises questions about the security risks inherent in storing comprehensive personal and financial data tied to cryptocurrency holdings.
- Revolut confirmed fraudsters used a legitimate government agency email domain to request customer data, which the platform released believing the request was genuine.
- Exposed data included passports, driving licenses, home addresses, bank statements, and full Bitcoin transaction records for a limited number of customers.
- Revolut stated customer accounts remain secure with no unauthorized access to passcodes, login credentials, biometric data, or funds.
- Limited Number of affected customers contacted by Revolut following the data exposure incident
- Wealthy Users appear to have been targeted according to blockchain investigator analysis
Revolut disclosed that fraudsters conducted a sophisticated impersonation attack, leveraging a legitimate government agency email domain to submit false data requests that the fintech platform processed as authentic. The company confirmed it released customer information including passports, verification selfies, driving licenses, home addresses, bank statements, and complete records of Bitcoin transfers to and from customer accounts. Revolut stated it identified and blocked the sender immediately upon discovery, then notified the relevant government agency, law enforcement, and its financial regulators and data protection authorities.
Evolving threat landscape for Fintech platforms
The incident illustrates a growing class of attacks targeting financial service providers through social engineering and impersonation rather than direct technical exploitation. As fintech platforms have proliferated and regulatory oversight has increased, legitimate data requests from government agencies have become routine, creating both operational necessities and potential vulnerabilities. Revolut and similar platforms must balance the need to comply promptly with lawful government requests against the risk of processing fraudulent submissions.
This attack method represents a lower-cost alternative to conventional cybersecurity attacks like SQL injection or zero-day exploits. Sophisticated social engineers can research legitimate government agency communications, replicate formatting and procedures, and exploit institutional familiarity with regulatory compliance workflows. The tactic succeeds by targeting organizational processes rather than technical infrastructure.
Revolut confirms passport and Bitcoin records reached attackers
Revolut’s official statement to customers framed the incident as a breach of specific data categories. The company said verification selfies were included in the compromised information, though it clarified that biometric facial telemetry, the algorithmic face template generated during identity verification, was not exposed. The distinction matters because the photograph itself represents a distinct privacy exposure even if the underlying biometric identifier was not accessed.
Blockchain investigator ZachXBT, who specializes in tracing stolen cryptocurrency, first publicly flagged the leak and noted that the targeting appeared focused on a small subset of users with substantial holdings. The exposure of full Bitcoin transaction histories creates a documented record of wealth for affected customers, a particular risk given the public and permanent nature of blockchain data.
The comprehensive nature of the exposed data is particularly concerning for cryptocurrency holders. Unlike traditional financial records that may be subject to privacy regulations limiting distribution, Bitcoin transaction histories represent an immutable public ledger that links wallet addresses to real-world identities. Once that connection is established through leaked know-your-customer data, the link cannot be undone.
Accounts remain accessible but Data access questions remain
Revolut maintained that customer accounts themselves were not compromised and remained fully secure. The company stated that passcodes, login credentials, and biometric data stored on its systems were never accessed or exposed. No unauthorized fund transfers occurred, and the attacker gained no ability to log into customer accounts or move money.
This distinction is important for understanding the scope of the breach. The attackers obtained a snapshot of historical customer data through what amounted to a fraudulent records request, rather than establishing persistent unauthorized access to the platform itself. Customers did not need to reset passwords or enable enhanced security measures on their accounts.
Revolut declined to identify which government agency’s email domain was exploited, citing an active police investigation. This leaves unresolved a critical question about the attack vector: whether a government email account was compromised and hijacked to send the fraudulent data request, or whether someone with internal access to the agency’s email system initiated the request directly.
Data retention practices under scrutiny
The incident has renewed debate within the fintech and cryptocurrency industries about data retention policies. Regulators in many jurisdictions require platforms to maintain comprehensive customer records for anti-money laundering and know-your-customer compliance. However, the security risks of maintaining centralized databases of sensitive personal information and complete financial histories have prompted some companies to explore minimization strategies and encryption techniques that limit what can be extracted in a single breach.
Stolen Data sets risk escalation beyond initial Breach
Leaked customer lists have historically preceded phishing attacks and social engineering campaigns targeting victims of previous breaches. Combined with home addresses and full financial histories, the exposed data creates vectors for both digital fraud and physical targeting of cryptocurrency holders. Criminals can use the leaked information to craft convincing phishing emails referencing specific Bitcoin transactions or to conduct extortion campaigns against identified wealthy individuals.
The targeting of affluent users suggests attackers conducted reconnaissance to identify high-value victims, then focused their fraudulent data request on customer accounts most likely to contain substantial holdings. This represents a more sophisticated attack than untargeted breaches that compromise entire customer databases indiscriminately.
Revolut has not disclosed the timeline between when the fraudulent request was submitted and when it was detected and blocked, or identified the specific government agency whose email domain was used in the attack. The ongoing police investigation may eventually establish whether the compromise was external or involved insider access, a distinction that carries significant implications for government email security practices and the broader vulnerability of social engineering attacks against regulated service providers.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
