TechNewsReel
Live

Revolut Leaked Customer Passports and Bitcoin Data in Government Impersonation Scam

The digital bank handed over sensitive KYC records and transaction histories after falling for a fraudulent request sent from a legitimate government domain.

TechNewsReel Newsroom · September 12, 2026

Digital bank Revolut has inadvertently exposed sensitive customer data after fulfilling a fraudulent request from an attacker posing as a government agency. The breach occurred when the company treated a request sent from a real government domain as legitimate, leading to the unauthorized release of personal records.

Confirmed reports indicate the exposed data includes passports, KYC (Know Your Customer) selfies, and residential addresses. Critically, the leak also included Bitcoin transaction histories, directly linking cryptocurrency activity to the personal identities of the affected users.

The Vulnerability of Verification

This incident underscores a systemic vulnerability in how financial institutions verify official data requests. While many firms rely on the domain of an incoming email to establish trust, this case demonstrates that attackers can utilize or spoof legitimate government domains to bypass standard security controls. By leveraging a trusted source, the impersonators deceived Revolut's internal verification processes, resulting in the handover of highly sensitive documentation without further validation.

Implications for Blockchain Privacy

The consequences of this leak are particularly severe due to the nature of the data involved. Bitcoin transactions are pseudonymous, meaning that while the ledger is public, the identities of the wallet owners typically remain hidden. By tying these transaction histories to real-world names, home addresses, and passport details, the breach effectively strips away the privacy layer of the blockchain for the impacted users.

This deanonymization creates significant risks for high-net-worth individuals and crypto investors. The availability of residential addresses alongside financial holdings makes users vulnerable to targeted phishing attacks, extortion, or physical security threats. The intersection of KYC data and blockchain activity transforms a digital ledger into a roadmap for malicious actors.

Industry Outlook

Industry analysts suggest this breach will likely prompt a shift in how fintech companies handle regulatory requests. The reliance on email domains as a primary trust signal is now proven insufficient. Moving forward, financial institutions may be forced to implement multi-channel verification or secure portals for government data exchanges to prevent similar impersonation attacks.

It remains to be seen how many users were affected by the leak and what remediation steps Revolut will offer to those whose physical addresses and financial histories have been exposed. For now, the incident serves as a stark reminder that even sophisticated digital banks can be compromised by basic social engineering when it is paired with a trusted domain.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.