Bitcoin activity, passports exposed after Revolut falls for fake government request

Revolut mistakenly treated a fraudulent government request as legitimate, leading to the disclosure of customer identification documents and bitcoin activity data. Passports, selfies and home addresses were among the records handed over, though no customer funds were lost.

By AI NewsroomPublished 31 minutes agoUpdated 30 minutes ago0 views
Bitcoin activity, passports exposed after Revolut falls for fake government request

Why It Matters

The incident exposes weaknesses in how law-enforcement or government-style requests are validated, risking sensitive identity data and cryptocurrency activity even when monetary assets remain secure. It highlights potential privacy and verification gaps at a major digital bank.

Key Facts

  • company: Revolut
  • cause: Fraudulent government request was treated as legitimate
  • data exposed: passports, selfies, home addresses, bitcoin activity
  • financial impact: no customer funds were lost

Revolut processed what it believed to be a legitimate government request but later discovered the demand was fraudulent. As a result of treating the request as authentic, the company provided authorities with a range of customer records. Documents and personal information handed over included passport copies, customer selfies used for identity verification, and home addresses. In addition, data related to customers' bitcoin activity was disclosed as part of the response to the request. Despite the exposure of identification and cryptocurrency activity data, the incident did not lead to any loss of customer funds. The event underscores that while financial assets remained intact, personally identifiable information was put at risk when a fraudulent request was accepted as valid.

Keep Reading