Blockchain AcademicsBlockchain Academics
Revolut Exposed Customer Passports and Bitcoin Transaction Data After Fake Government Request

Revolut Exposed Customer Passports and Bitcoin Transaction Data After Fake Government Request

Revolut confirmed a data breach affecting a limited number of users after fraudsters spoofed a government agency email and requested sensitive customer information including passports and complete Bitcoin transaction histories.

Blockchain Academics NewsroomEdited by Ibrahim RajabSeptember 12, 20263 min read
Share

Revolut Exposed Customer Passports and Bitcoin Transaction Data After Fake Government Request

Revolut disclosed sensitive customer data, including identity documents and full Bitcoin transaction histories, after fulfilling a fraudulent information request sent from a spoofed government agency email domain. The fintech giant confirmed the breach on September 12, 2026, describing the number of affected users as "limited" without providing a specific count.

The exposed data spans KYC (know-your-customer) records, passport scans, and complete cryptocurrency activity histories. That combination is particularly damaging: KYC documents alone enable identity fraud, but pairing them with detailed crypto transaction records creates a precise map of a user's financial behavior and holdings.

Fraudsters spoofed an official government agency email domain, sending what appeared to be a legitimate law enforcement or regulatory data request. Revolut's internal processes did not catch the forgery before the data was handed over. The company has not disclosed which government agency was impersonated, which jurisdiction was involved, or how long it took to identify the request as fraudulent.

Onchain investigator ZachXBT speculated the operation was deliberately targeted at high-net-worth users, which would explain why attackers constructed a convincing government impersonation rather than pursuing a broader, less precise attack. If accurate, that framing shifts the incident from a passive data leak to an active, targeted extraction of valuable financial intelligence.

The failure points to a gap in Revolut's request verification workflow. Regulated financial institutions operating across multiple jurisdictions routinely receive data requests from law enforcement and government agencies. Best practice requires multi-step verification: confirming the requesting authority through an independent channel, validating the legal basis for the request, and in some cases requiring requests to pass through formal legal portals rather than standard email. A spoofed domain should not clear those checks.

This is not the first time a major financial platform has been compromised through social engineering. The tactic of impersonating government authorities to extract data has grown more sophisticated alongside the expansion of fintech compliance infrastructure. The more processes a company builds to respond quickly to official requests, the more attractive those processes become as an attack surface. Coinbase disclosed in May 2025 that overseas contractors had been bribed to leak customer data, a different vector but the same outcome: KYC records and account details in the wrong hands.

For Revolut's customer base, the immediate concern is targeted phishing and SIM-swapping attacks. Anyone holding significant Bitcoin through the platform whose data was exposed now faces a credible risk of follow-on fraud. Users who believe they may be affected should consider rotating authentication credentials, enabling hardware-key two-factor authentication where available, and treating any inbound communications referencing their Revolut account with heightened skepticism.

Revolut did not immediately respond to questions about remediation steps, regulatory notifications, or whether affected users have been individually notified. Under GDPR, which applies to Revolut's European operations, the company is required to notify the relevant supervisory authority within 72 hours of becoming aware of a breach and to inform affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Exposure of passport data and financial records almost certainly clears that threshold.

The incident underscores the need for a standardized, independently audited verification protocol for government data requests, one that cannot be bypassed by a convincing email address.

Discussion

Loading comments...