Revolut Exposed Passports and Bitcoin Records After Fake Government Request

iEXExchanger
Revolut Exposed Passports and Bitcoin Records After Fake Government Request

A forged government email fooled Revolut's checks, and the bank handed over passports, selfies and Bitcoin transaction histories. No funds were touched, but the leak is a scammer's dream.

A single email dressed up as an official government request slipped past Revolut's checks — and the bank handed over a batch of customer data in response. Only afterward, when Revolut contacted the agency directly, did it learn the request had never been sent by anyone there.

The breach is narrow but nasty. Whoever received the reply now holds passports and driving licenses, verification selfies, home addresses, dates of birth, IBANs and, separately, a full history of Bitcoin activity — wallet references, withdrawal amounts, complete transaction records. Facial biometric telemetry wasn't part of the haul, which Revolut says is a distinct category from the verification selfies that were exposed.

The failure sat in the vetting process itself. The forged email carried credentials that passed Revolut's internal authentication as a genuine official request — convincing enough on paper, fake underneath. The bank released the data first and caught the forgery only later, after checking with the agency directly.

No money moved. Account balances stayed untouched. But a passport paired with a crypto transaction history is exactly the bait scammers need for targeted follow-up attacks — the classic play of posing as an exchange, a bank or "support" to squeeze a crypto holder for access. On-chain investigator ZachXBT flagged that the leak looked narrow rather than mass, hinting the attacker may have gone after high-balance accounts specifically.

Revolut says it has blocked the compromised email address across its systems, notified affected customers on September 11, alerted regulators, and warned the impersonated agency that its name was being used in fraudulent mail. It still hasn't said how many customers were caught up in the leak — the one number everyone actually wants.

Questions and answers

Frequently asked questions about this article

What happened at Revolut?

Scammers sent Revolut an email formatted as an official government request. It passed the bank's internal authentication checks, and Revolut released a batch of customer data in response. It later found the real agency had never sent the request.

What customer data was exposed?

The leak included passports and driving licenses, verification selfies, home addresses, dates of birth, IBANs, and a separate full history of Bitcoin activity — wallet references, withdrawal amounts and complete transaction records.

Were customer funds affected?

No. Revolut confirmed the breach didn't grant access to accounts or funds. The real risk is different: a passport paired with a crypto transaction history is exactly what scammers use for targeted attacks on high-balance holders.

What is Revolut doing about it?

Revolut blocked the compromised email address across its systems, notified affected customers on September 11, alerted regulators, and warned the impersonated agency that its name was being used in fraudulent mail. It hasn't disclosed how many customers were affected.