Revolut Gave Customer Passports and Bitcoin Records to Fraudster Posing as Government Agency

Revolut Gave Customer Data to Scammers After Fake Government Requests

Revolut handed over highly personal and sensitive customer data, including passports, verification selfies, IBANs, and Bitcoin transaction records, to scammers after they sent requests through a government agency email domain.

Listen to this article

0:00

Press play to start listening

Revolut, the London, United Kingdom-based global digital banking and financial technology platform, provided sensitive customer information to an unauthorized third party after being tricked by fraudulent requests sent through the legitimate email domain of a government agency.

The incident did not involve attackers breaching Revolut’s systems. Instead, the fraudulent requests came from an unauthorized email account using the government agency’s official domain and carried valid domain authentication credentials.

Revolut said it fulfilled the requests under the belief that they were authentic government requests. The company later contacted the government agency to verify the requests, which led to the discovery that the email account was unauthorized.

Passports, Selfies and Financial Records Disclosed

The information disclosed varied by customer but included highly sensitive identity and financial records. Revolut’s notification lists full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers.

Worse, copies of passports and/or driving licences were also disclosed, along with facial verification images provided during identity checks. Revolut normally collects identity documents and selfie images as part of its customer verification process.

The exposure was not limited to identity documents. The scammers also obtained detailed financial records, including account statements with IBANs, account status, opening dates and wallet reference numbers, along with withdrawal records and complete transaction histories, including Bitcoin transactions. Meanwhile, the fintech giant stressed biometric facial telemetry was not compromised in the incident.

Revolut Gave Customer Passports and Bitcoin Records to Fraudster Posing as Government Agency
Revolut notification sent to impacted customers

Former Mt. Gox CEO Mark Karpelès was among the recipients of a Revolut notification and published excerpts from the email on X. Blockchain investigator ZachXBT also reported the incident, saying it appeared to affect a relatively small number of users and may have been directed at high-net-worth customers.

Revolut itself has not publicly confirmed that affected customers were selected because of their wealth. However, the company’s official support account responded to a query about the incident with a standard support response, stating, “We take data protection and privacy concerns very seriously.”

Hi there. We take data protection and privacy concerns very seriously. If you have any questions or need further assistance regarding this notification, please send us a DM via @RevolutSupport so we can look into this for you— Revolut Support (@revolutsupport) September 12, 2026

Government Agency Not Identified

Revolut has not identified the government agency whose domain was used. The company told Hackread.com that it had identified what it described as a “sophisticated external impersonation attack” involving an unauthorized third party using a legitimate government agency domain to submit fraudulent information requests.

After identifying the fraudulent activity, Revolut blocked the email address from its systems and alerted the affected government agency. The company also notified police, financial and data protection regulators, and affected customers. Revolut said its systems and customer funds were unaffected.

The company has not disclosed how many fraudulent requests it processed, how many customers were affected, when it provided the information, or whether the attacker used the stolen records elsewhere.

The incident is therefore different from a conventional data breach in which attackers gain unauthorized access to a company’s infrastructure. In this case, the available evidence indicates Revolut itself released the information after accepting fraudulent requests as legitimate.

The exposed combination of identity documents, contact details, and financial histories could also provide information useful for highly personalized phishing or impersonation attempts. Revolut advises customers receiving suspicious communications not to disclose financial information and to contact the company through official channels.

Revolut and Cybersecurity Issues

This is not the first security-related incident involving Revolut. In 2023, Hackread.com reported that criminals exploited a flaw in the company’s US payment system, causing about $23 million in losses before some funds were recovered, leaving Revolut with a net loss of about $20 million. The flaw caused declined transactions to be incorrectly refunded using Revolut’s own money.

Revolut was also among the companies targeted by hackers associated with Lapsus$. During a 2023 UK trial involving Arion Kurtaj and another teenager, prosecutors detailed attacks against several major companies, while evidence presented in the case showed that Kurtaj had hacked Revolut and Uber while on bail.

(Photo by Aleksandrs Karevs on Unsplash)

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts