Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeBusiness › Bitcoin activity, passports exposed after Revolut falls for fake government request
Business

Bitcoin activity, passports exposed after Revolut falls for fake government request

By Diego Whitfield · · 2 min read

Digital banking giant Revolut has confirmed that sensitive customer data, including passports, selfies, home addresses and Bitcoin transaction records, was exposed after the company mistakenly acted on a fraudulent government data request, the firm disclosed on Saturday.

What Happened

Revolut said it treated a bogus request for information as if it had come from a legitimate government authority, handing over personal details belonging to an unspecified number of customers. The compromised information included identity documents such as passports, verification selfies, residential addresses and records tied to customers' Bitcoin activity.

The incident highlights a growing threat facing financial institutions: so-called emergency or fraudulent government data requests, in which bad actors impersonate law enforcement or regulatory bodies to trick companies into surrendering user information.

No money was taken, but for affected users the exposure of passports and crypto records is a breach that can't simply be reversed.

No Funds Lost, But Data Exposed

Crucially, Revolut emphasized that no customer funds were stolen as a result of the breach. The exposure was limited to personal and identity-related data rather than access to accounts or balances.

Still, the leak of highly sensitive material poses lasting risks for those affected. Passport scans and identity selfies can be exploited for identity theft, while exposed Bitcoin transaction histories may compromise the financial privacy of crypto-holding customers.

Key details of the incident include:

  • Passports and verification selfies were among the leaked documents
  • Home addresses and Bitcoin activity records were also exposed
  • No customer funds were lost in the event
  • Revolut has acknowledged it fell for a fake government request

The Broader Risk

The episode underscores the vulnerability of even large, well-resourced fintech firms to social engineering attacks. Fraudulent data requests have become an increasingly common tactic, exploiting the trust that companies place in official-looking demands from authorities.

For crypto users in particular, the breach is a reminder that centralized platforms holding identity and transaction data remain attractive targets. Revolut has not yet detailed how many customers were affected or what steps it will take to prevent similar incidents in the future.

Was this useful?👍 Yes👎 No