Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Revolut has begun notifying customers that it disclosed their personal data to an unauthorized third party after receiving what it believed was a legitimate <a href="https://xpertsstudio.com/revolut-confirms-sending-passport-and-bitcoin-records-to-fake-government-email/” title=”Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email”>government request. The request was fraudulent. The fintech says it came from an email account that operated directly within an official government agency’s domain infrastructure, passed standard authentication checks, and carried credentials that made it indistinguishable from the real thing.
The company’s statement describes the incident as a “sophisticated external impersonation attack.” What it describes is an email. One email, sent from the right domain, with the right headers, asking for customer files. Revolut complied.
What Was Disclosed
According to customer notices shared by blockchain investigator ZachXBT, the disclosed data included copies of identity documents such as passports and driver’s licenses, along with the selfies customers submitted for identity verification. Account statements were also provided, including IBANs, account status, account-opening dates, and Bitcoin wallet reference numbers. Full transaction histories, including Bitcoin transactions, were handed over.
Revolut drew a distinction between the selfie images and derived biometric facial telemetry, the latter of which it says was not involved. The company also says no login credentials, passwords, or account access was compromised. Customer funds remain unaffected.
For anyone whose identity documents and transaction records were both disclosed, the recipient now possesses a detailed financial profile tied to a verified real-world identity. This is the exact combination that enables targeted phishing, fraudulent account creation, and, in more severe cases, physical threats against cryptocurrency holders. Similar data exposures in the crypto space have preceded both.
A Known Attack Vector
This kind of social engineering is not new. As far back as 2022, security researcher Brian Krebs documented how attackers were spoofing emergency data requests to extract customer information from service providers. The proposals to solve this, such as requiring digital signatures on government requests, have not been widely implemented. Even if they were, they would not fully address the problem of compromised accounts operating within legitimate government infrastructure.
Financial institutions receive government data requests constantly. Law enforcement inquiries, court orders, regulatory demands. They are built to comply with these when properly verified. What happened at Revolut is a failure of that verification layer, not a technical breach in the conventional sense. No malware was involved. No credentials were stolen. The data walked out the front door.
Who Was Affected
Revolut has not disclosed how many customers were included in the response, which government agency’s domain was used, or when the data was released. ZachXBT indicated the breach appears to have targeted a small subset of users, likely high-net-worth individuals rather than a broad customer base. Customers received notification emails on September 11.
The company says it has blocked the unauthorized email address across all internal systems, notified relevant regulators, and applied precautionary protection measures for affected customers. It has also alerted the impersonated government agency about the unauthorized account operating within its domain.
Revolut serves more than 70 million customers worldwide as of January 2026, making it the largest digital bank in Europe. The company earned $6 billion in revenue in 2025 and secured its UK banking license in March 2026.
For affected customers, the advice is straightforward but limited in comfort. Treat any unexpected communication referencing the leak as high risk. The exposed records contain exactly the details attackers would use to impersonate customer service, initiate account recovery workflows, or construct convincing pretexts for further fraud. A password can be changed in a minute. A passport cannot.
Source: glitchwire.com
