Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request
Revolut disclosed sensitive customer records, including passport copies, verification selfies and complete Bitcoin transaction histories, after honoring a fraudulent information request that used a government agency's legitimate email domain. The company says the incident was a sophisticated impersonation scam affecting a "limited" number of customers and that systems and customer funds were not impacted.

Why It Matters
The leak exposes personally identifiable information and full crypto transaction histories, raising concerns about targeted attacks on wealthy crypto holders and the security trade-offs of extensive know-your-customer (KYC) data collection. It also follows other recent incidents where firms that hold crypto users' personal data were compromised.
Key Facts
- exposed-data: Passport or driver's license copies, verification selfies, full name, date of birth, occupation, postal address, email, phone number, IBAN and wallet reference numbers, withdrawal records and full Bitcoin transaction histories
- attack-method: Fraudulent request submitted from an unauthorized email account using a government agency's official domain and valid domain authentication credentials
- revolut-confirmation: Described the incident as a "sophisticated external impersonation scam" to TechCrunch
- customers-affected: A "limited" number, per Revolut; company declined to provide specific figures
- agency-identified: Revolut declined to name which government agency's domain was impersonated
Fintech firm Revolut has revealed that it supplied sensitive customer records to a malicious actor after responding to a fraudulent information request that appeared to originate from a government agency's official email domain. The request used valid domain authentication, which led Revolut to treat it as genuine and fulfill the data demand.
Customer-facing documents circulated by crypto investigator ZachXBT indicate the disclosed information was extensive: identity data (including passport or driver's license images and verification selfies), contact details, account statements with IBANs and wallet reference numbers, withdrawal records and full transaction histories for Bitcoin. Revolut said no biometric facial telemetry data was involved.
A company spokesperson told TechCrunch the breach was "a sophisticated external impersonation scam." Revolut said it blocked the offending email address and notified the impersonated agency, law enforcement and regulators. The firm maintained that its systems and customer funds were not affected, but it did not disclose how many people were impacted or the name of the agency whose domain was spoofed.
Security observers raised alarm about the likely profile of victims. ZachXBT suggested the incident targeted high-net-worth users, fueling worries about so-called "wrench attacks" against public crypto holders. The episode has also prompted criticism on social media that extensive KYC requirements concentrate sensitive data and create new risks. The leak comes as other companies handling crypto users' data have reported breaches, and as Revolut — which launched a euro-pegged EURR stablecoin this year — evaluates a potential IPO.
Keep Reading

Automattic confirms Mullenweg has returned as CEO after attempted ouster by board

OpenAI IPO won't happen this year, says Sam Altman
