TechNewsReel
Live

Revolut Leaks Passports and Bitcoin Data via Government Impersonation Scam

The fintech giant disclosed sensitive identity documents and crypto records after trusting fraudulent requests sent from a legitimate government email domain.

TechNewsReel Newsroom · September 14, 2026

Revolut disclosed sensitive customer data to scammers who impersonated a government agency, exposing users to significant identity theft risks. The breach, brought to public attention by crypto researcher ZachXBT on September 12, 2026, occurred after the company fulfilled fraudulent data requests without sufficient verification.

According to reports from Decrypt and CyberInsider, the attackers utilized a legitimate government email domain to send requests for user information. Revolut complied with these requests, resulting in the leak of highly sensitive personal identifiers. The compromised data included passport copies, driver's licenses, facial verification selfies, telephone numbers, and email addresses. Furthermore, the breach specifically exposed full Bitcoin transaction histories and detailed account records for the platform's cryptocurrency users.

Regulatory Pressure and Scaling

Revolut is a London-based fintech neobank that currently serves over 80 million customers globally. While the company operates under the regulatory oversight of bodies such as the Financial Conduct Authority (FCA) in the UK, it has faced persistent scrutiny regarding its security protocols and compliance frameworks. This incident occurs as the firm continues to scale its operations and pursues a full banking license, a process that requires rigorous adherence to data protection and risk management standards.

The Danger of Domain Trust

This breach highlights a critical vulnerability in corporate verification processes: an over-reliance on the perceived authenticity of email domains. By trusting a request simply because it originated from a recognized government domain, Revolut bypassed its own security layers. This failure is particularly damaging for high-value cryptocurrency holders, as the combination of government-issued IDs and full Bitcoin transaction histories provides fraudsters with the necessary tools for targeted financial attacks and sophisticated identity fraud.

Future Outlook

Industry analysts are now watching to see how Revolut updates its internal verification workflows to prevent similar social engineering attacks. It remains to be seen whether regulatory bodies will impose fines or mandate specific security audits following the disclosure. For now, affected users are advised to monitor their accounts for unauthorized activity, while the industry at large is reminded that domain authenticity is not a substitute for multi-factor verification of legal requests.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.