Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeBusiness › Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request
Business

Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request

By Diego Whitfield · · 2 min read

Fintech giant Revolut has confirmed that it handed over sensitive customer data, including passport images and complete Bitcoin transaction histories, in response to a fraudulent government information request that appeared to originate from a legitimate agency's own email domain.

How the Breach Unfolded

The incident stemmed from a so-called "emergency data request," a mechanism law enforcement and government agencies use to compel information from companies under urgent circumstances. In this case, the request was fake, but it was convincing enough to slip past Revolut's verification processes because it was sent from an email address tied to a genuine government domain.

By fulfilling the fraudulent request, Revolut exposed identity documents and full cryptocurrency transaction records belonging to affected users. The company has characterized the number of impacted customers as "limited," though the exposure of both government-issued ID and detailed crypto activity represents a serious privacy risk for those involved.

A single spoofed email carried enough authority to unlock passports and entire Bitcoin transaction histories.

Why It Matters

The episode highlights a growing weakness in how financial platforms handle data requests that appear to come from official sources. Attackers increasingly exploit compromised or spoofed government email systems to trick companies into surrendering user information without the usual legal safeguards.

For crypto users, the stakes are particularly high. Exposed transaction histories can be used to trace holdings, link wallets to real-world identities, and potentially set up targeted phishing or extortion attempts. Combined with leaked passport images, the data offers bad actors a powerful toolkit for identity theft.

Key concerns raised by the incident include:

  • The ease with which a fraudulent request bypassed verification checks
  • The sensitivity of combining ID documents with full crypto records
  • The broader vulnerability of emergency data request systems across the industry

The case serves as a warning for fintech firms to tighten their authentication procedures for government-linked requests, even when they appear to arrive from trusted domains.

Was this useful?👍 Yes👎 No