Revolut Disclosed Customer Passports and Bitcoin Histories to Fraudulent Government Requester
Revolut disclosed customer passports and Bitcoin transaction histories after fulfilling a fraudulent data request sent from an authentic government email domain. While customer funds remained safe, the incident leaked complete identity dossiers belonging to targeted cryptocurrency users.
Owen Li
Editor-in-Chief
- Jurisdictions
- Global
- Published
- Reading time
- 3 min read
British fintech and banking provider Revolut has disclosed comprehensive customer compliance records—including passport scans, verification selfies, and complete Bitcoin transaction histories—after falling victim to a fraudulent data request sent from inside a legitimate government agency’s email infrastructure.
The incident, confirmed by the company on September 12 following initial reporting by TechCrunch, highlights a critical vulnerability in how financial platforms verify official data requests. While Revolut emphasized that its core infrastructure was not breached and customer balances remain untouched, the handover delivered complete identity and financial dossiers of targeted users directly to an unauthorized third party.
The Verification Breakdown
Unlike conventional data breaches involving malware or exploited databases, the exposure resulted from a breakdown in operational verification. The attacker obtained access to an unauthorized mailbox operating within the genuine domain infrastructure of an official government agency.
Because the communication originated from valid agency servers, the incoming request cleared standard domain-level email authentication protocols, including SPF, DKIM, and DMARC. Relying on those technical indicators, Revolut’s compliance personnel fulfilled the inquiry under the belief that it was an authentic legal demand.
Revolut discovered the fraud only after handing over the data. When staff reached out to the government agency via independent channels to follow up, the agency confirmed it had never authorized or submitted the inquiry.
Complete KYC Dossiers Released
Breach notifications emailed to affected customers starting September 11 reveal an exhaustive inventory of disclosed Know Your Customer (KYC) records:
- Personal & Contact Details: Full legal names, birth dates, occupations, physical residential addresses, phone numbers, and email addresses.
- Identity Documents: Scans of government-issued IDs, including passports and driver’s licenses, alongside onboarding facial verification selfie photos (Revolut noted that raw biometric telemetry data was not involved).
- Financial & Crypto Ledgers: Bank account statements, IBANs, wallet reference numbers, withdrawal records, and complete transaction histories, explicitly including Bitcoin activity.
Account credentials, card PINs, and cryptocurrency private keys were not included in the disclosure.
Targeted Wealth Profiles and Crypto Exposure
Although Revolut characterized the incident as affecting a "limited number" of users, onchain researcher ZachXBT assessed that the attack was highly focused, appearing to target high-net-worth individuals and prominent cryptocurrency holders. Former Mt. Gox chief executive Mark Karpelès confirmed he was among the victims, making public the notification he received from Revolut. Marc Zeller, founder of the Aave Chan Initiative, also voiced frustration, noting the disclosure followed shortly after intensive compliance and verification demands from the platform.
The exposure of cryptocurrency transaction histories presents unique security concerns. While blockchain records are public, transactions are pseudonymous. By pairing historical onchain activity with verified identity documents, home addresses, and phone numbers, the compromise permanently de-anonymizes affected wallets—substantially elevating the risk of SIM-swap attacks, spear-phishing, and physical extortion schemes.
Industry-Wide Implications
Revolut confirmed it blocked the sender mailbox and alerted law enforcement, relevant data-protection bodies, financial regulators, and the compromised agency. However, the company has declined to publicly name the agency or specify which national jurisdictions were affected.
Security analysts have criticized this silence, emphasizing that withholding the agency's domain prevents other banks, fintechs, and crypto exchanges from auditing their own legal-inbox logs for identical fraudulent inquiries.
The incident comes as Revolut, serving 80 million users globally, pursues a U.S. national bank charter after securing conditional approval from the Office of the Comptroller of the Currency. It also highlights a broader structural hazard across the sector: as financial regulations compel platforms to assemble exhaustive identity dossiers, relying on unverified email channels to fulfill law enforcement requests turns centralized compliance vaults into prime targets for social engineering.
Topics and entities
- Topics
- Privacy & Security