Revolut Leaked Customer Passports and Bitcoin Data in Government Impersonation Scam
The fintech giant handed over sensitive identity documents and transaction histories after falling for a fraudulent request from a fake government domain.
Revolut has disclosed that it handed over sensitive customer data to fraudsters who impersonated a government agency. The incident reveals a significant lapse in the company's verification process for regulatory data requests.
According to reports from CoinDesk and BeInCrypto, the exposure occurred when Revolut processed a fraudulent request from an attacker using a government-themed domain. This impersonation bypassed the company's internal security checks, leading Revolut to voluntarily disclose a trove of private information. The exposed data included passports, verification selfies, residential addresses, and comprehensive transaction histories, with a specific emphasis on Bitcoin activity.
The Compliance Gap
Financial institutions operate under strict Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations, which mandate compliance with legitimate government data requests. However, this regulatory requirement has created a new attack vector. Threat actors are increasingly employing corporate-level social engineering, mimicking regulators to trick compliance officers into releasing bulk data. Unlike individual user requests, which typically undergo rigorous verification, these high-level impersonations exploit the perceived authority of government agencies to bypass standard security protocols.
Risks to Crypto Users
This breach is particularly critical due to the nature of the leaked information. By pairing real-world identity documents—such as passports and selfies—with detailed Bitcoin transaction histories, the attackers have effectively stripped away the pseudonymity of the affected users. This combination creates a high risk of targeted phishing campaigns, identity theft, and potential physical security threats for individuals with significant cryptocurrency holdings.
Revolut has attempted to mitigate alarm by stating that its internal systems were not breached and that customer funds remain safe. However, the loss of identity documents and financial footprints represents a permanent compromise of user privacy that cannot be resolved by simply securing funds.
Industry Implications
Industry analysts suggest this incident highlights a systemic vulnerability in the "trust layer" of fintech compliance. As digital banks scale their operations, the pressure to comply quickly with regulatory demands may be outpacing the implementation of robust verification frameworks for those demands.
What remains to be seen is whether other fintech firms have fallen victim to similar government-themed impersonation schemes. For now, the incident serves as a warning that even sophisticated financial platforms can be compromised not through a technical hack, but through the manipulation of their own compliance procedures.