Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request
Revolut disclosed that a malicious actor obtained sensitive customer data by sending a fraudulent information request that appeared to come from a government agency’s official domain. Because the email had valid domain authentication, Revolut treated it as legitimate and complied. The exposed information included full names, birth dates, occupations, contact details, identity documents such as passport or driver’s license copies, verification selfies, account statements, IBAN and wallet reference numbers, withdrawal records, and full transaction histories, including Bitcoin activity. Revolut said biometric facial data was not involved. The company said only a limited number of customers were affected, the attacker’s email was blocked, and authorities were notified. Revolut said its systems and customer funds were not impacted and did not identify the agency or number of victims. The incident has raised concerns because it may have targeted high-value crypto users and highlights risks created by KYC data collection.
