Revolut Leaks Passports and Bitcoin Data via Government Impersonation Scam
The fintech giant disclosed sensitive identity and financial data after an attacker used a legitimate government email domain to bypass authentication checks.
Revolut has confirmed a significant data breach after falling victim to a sophisticated impersonation scam that tricked the company into releasing sensitive customer information. The incident, which occurred in September 2026, underscores a critical failure in how the fintech giant verifies official data requests.
According to a Revolut spokesperson, an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information. Because the requests originated from an official domain, they passed Revolut's internal authentication checks. The resulting leak exposed a massive array of personal identity documents, including full names, dates of birth, phone numbers, email and postal addresses, and copies of driver's licenses and passports.
Beyond identity theft risks, the breach included highly sensitive financial records. Leaked data comprised account statements, IBANs, and wallet reference numbers. Most notably, the attacker gained access to complete transaction histories, specifically including Bitcoin (BTC) records. Reports indicate the incident appeared to specifically target high-net-worth users, with former Mt. Gox CEO Mark Karpelès identified as one of the affected customers.
Strategic Timing and Market Pressure
This security failure arrives at a precarious moment for Revolut. The company currently serves over 80 million customers globally and is weighing a potential initial public offering (IPO) with valuations estimated as high as $200 billion. Furthermore, Revolut recently received conditional approval from the US Office of the Comptroller of the Currency (OCC) to establish a national bank in the United States, with a target launch date of 2027.
Industry Implications
The breach highlights a systemic vulnerability in the fintech sector: the over-reliance on domain-level trust for government verification. By proving that a legitimate email domain is not a sufficient proxy for identity, the attack suggests that mandatory Know Your Customer (KYC) data collection creates a high-value honeypot for attackers. The exposure of Bitcoin histories for wealthy individuals significantly increases the risk of targeted digital and physical attacks, as these records provide a roadmap of a user's wealth and movement.
Next Steps
Revolut has since blocked the fraudulent email address and notified the affected customers, law enforcement, and relevant regulators. While the company has contained the specific entry point, the incident leaves open questions regarding how many other requests may have been processed before the scam was detected and whether other fintechs are susceptible to the same impersonation tactics.