Revolut Leaks Passports and Bitcoin Data via Fake Government Requests
The fintech giant disclosed sensitive identity documents and transaction histories after falling for a sophisticated impersonation scam.
Revolut has confirmed a data breach that exposed sensitive customer information to an unauthorized third party. The incident occurred after the company failed to detect fraudulent information requests sent from a legitimate government agency email domain.
According to a Revolut spokesperson, the company identified a "sophisticated external impersonation scam" where the attacker used a government domain to bypass internal security checks. The resulting leak included birth dates, phone numbers, and postal and email addresses. Most critically, the breach exposed copies of identity documents, such as passports and driver's licenses, as well as verification selfies.
Financial data was also compromised. The exposed information included account statements and transaction histories, with a specific emphasis on Bitcoin records. Revolut has since blocked the fraudulent email address and notified the affected customers, as well as relevant regulators and law enforcement agencies.
The Vulnerability of Trust
This breach exposes a systemic weakness in how financial institutions verify legal and regulatory requests. While many firms rely on domain verification to authenticate government communications, this incident proves that the use of a legitimate domain can be enough to deceive internal security protocols. As AI tools make impersonation scams more convincing, the reliance on email-based verification becomes a significant liability for fintechs handling massive volumes of sensitive data.
Industry Implications
For the affected users, the exposure of passports and crypto transaction histories creates a high risk of targeted identity theft and fraud. The combination of government-issued IDs and specific financial activity—particularly Bitcoin records—provides attackers with a comprehensive toolkit for social engineering or account takeover attempts.
For the broader industry, the event serves as a warning that traditional security checks are insufficient against sophisticated actors. The breach comes as Revolut continues its aggressive global expansion, currently serving over 80 million customers across markets including France, the UAE, India, and Mexico. The scale of the user base amplifies the potential impact of any security failure, placing further pressure on the company to harden its verification pipelines.
What's Next
Revolut has not yet detailed whether it will implement new multi-factor authentication for government requests or move toward a more secure, non-email-based verification system. Industry observers will be watching to see if other fintechs audit their legal request processes to prevent similar impersonation attacks. It remains unclear exactly how many customers were impacted by the leak or if the stolen data has already been surfaced on dark web forums.