Revolut Exposes Passports and Bitcoin Data via Fake Government Request
Security

Revolut Exposes Passports and Bitcoin Data via Fake Government Request

September 13, 20264 min read

Fintech giant Revolut handed customer data to fraudsters after falling for a fake request that looked like it came from a government agency. The leak included passport copies, verification selfies, and full Bitcoin transaction histories for a batch of clients. The company says funds were unaffected, but crypto investigator ZachXBT warns the breach could expose wealthy crypto holders to physical attacks.

What exactly did the attackers get?

According to the International Cyber Digest account on X, the fraudulent request came from a mailbox inside a real government agency's own domain and passed Revolut's authentication checks. The bank later concluded the request was fake and notified affected customers separately. The company declined to name the agency or say how many customers were affected, describing the group only as "limited". Fintech firms are legally required to respond quickly to official law enforcement requests, and attackers relied on exactly that obligation.

Judging by the customer notice that ZachXBT made public, the scope of the exposed data is striking. It covers identity details (full name, date of birth, occupation), contact information (address, email, phone number), and documents including a passport or driver's license copy plus the verification selfie. Most concerning for crypto holders, attackers obtained account statements with IBAN and wallet reference numbers, withdrawal records, and full transaction history, including in Bitcoin. Revolut said no biometric facial data was involved.

Categories of leaked data
Identityname, date of birth, occupation
Documentspassport or license, verification selfie
Contactsaddress, email, phone
FinancesIBAN, wallet references, Bitcoin transaction history

How did scammers get past the bank's checks?

The scheme worked not because Revolut's systems were hacked, but because the company trusted someone else's domain. An attacker gained access to a mailbox inside a real government agency's domain and sent a formal request for customer data in the agency's name. The email's technical authentication, meaning a correct domain and valid headers, checked out, so Revolut's compliance team processed it as legitimate. Protocols like SPF or DKIM only confirm that a message came from an agency's real mail server. They say nothing about who actually typed a given email, so a hijacked account inside a government domain looks entirely genuine to the recipient.

Government agencies often run weaker mailbox security than banks or crypto exchanges, which is why they end up as the entry point for this kind of attack. Similar schemes have already been recorded against insurance companies and domain registrars.

  • Step one: the attacker compromises or creates an account inside the agency's genuine domain.
  • Next, a formal request for customer information goes out, citing the agency's lawful authority.
  • Revolut checks the sender's domain, sees a match, and skips calling the agency to confirm.
  • The data goes out before anyone catches the forgery.
The gist: Attackers did not breach Revolut's systems. They fooled the verification process using a real government mailbox.

Why does this hit crypto holders especially hard?

ZachXBT says the breach appears to have targeted customers with sizable holdings. Wallet reference numbers and transaction history let attackers estimate a victim's net worth before making any contact. Matching a wallet address against a public blockchain explorer is enough to see an approximate balance and transfer history without hacking anything else. That raises the risk of physical attacks on crypto holders, known in the community as "wrench attacks". Cases like this have been rising lately, and police in several countries have already logged attacks on people whose wallets became publicly known through leaks like this one.

Plenty of Ukrainians use Revolut, mostly for cross-border transfers and for reaching crypto markets while living abroad. For them, a leak like this is not an abstract risk but a concrete threat to personal safety. Extra caution with any message claiming to come from a bank or a government office is warranted, and so is avoiding posting wallet addresses alongside photos or location data.

"It was a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information."

- Revolut spokesperson, comment to Cointelegraph, September 13, 2026

What do security experts recommend?

On social media, users quickly pointed to the weak spot in KYC rules. To pass identity checks, customers hand banks a huge amount of sensitive data, with no guarantee it will be kept safe. One well-known DeFi developer wrote on X that identification procedures "hasn't produced meaningful upside and has put many in harm's way", a view that picked up plenty of support. Security researchers add a more practical tip for companies themselves: before handing over sensitive data in response to an official request, call the agency back using a number from public sources, not the one in the email itself.

Private keys tied to large sums are better kept off an exchange and inside a hardware wallet. Such a device doesn't depend on how well a fintech company protects its inbox, and it won't reveal a balance to anyone unless the owner does so themselves. A catalog of vetted devices is available in Kurslog's hardware wallets section. It's also worth turning on two-factor authentication inside Revolut itself and avoiding reusing the same ID documents for verification across dozens of services at once.

What happens next?

Revolut blocked the compromised address and notified the affected agency, law enforcement, and regulators. The leak did not happen in isolation. Hardware wallet maker Trezor recently admitted a vendor breach hit far more customers than first disclosed, while X suffered its own breach that flooded users with forced password resets.

Revolut launched its own EURR stablecoin this year and is weighing a stock market listing. The company operates under the watch of European data protection regulators, so an incident of this scale will almost certainly trigger a separate review. A fake government request probably won't derail those plans, but it will likely raise fresh questions for regulators about how fintech giants verify requests to hand over customer data.

Comments

Your email address will not be published. Required fields are marked *

or verify by email