Revolut Exposes Passports and Crypto Histories to Fake Government Request
Revolut handed over user passports and full crypto transaction histories to a hacker using a fake government email domain.

The update
Revolut disclosed that a sophisticated impersonation scam exposed sensitive customer data, including passport copies, verification selfies, and full Bitcoin transaction histories, for a limited number of users. The breach occurred after the fintech fulfilled a fraudulent information request that appeared to originate from a government agency. The request used the agency’s legitimate email domain, which passed authentication checks, leading Revolut to process the data transfer in good faith.
Why it matters
This incident highlights a growing vector for financial data theft: the exploitation of trusted domain credentials. By mimicking official government correspondence, attackers can bypass standard security protocols. The exposure of full transaction histories is particularly concerning for high-net-worth individuals, as it provides a complete audit trail of assets and movements.
What to watch
Regulators and affected users will likely scrutinize the exact number of victims and the specific agency impersonated. There are also questions regarding whether this is an isolated incident or part of a broader wave of attacks targeting fintechs. The use of “wrench attacks”—physical coercion combined with digital data theft—has been noted by security researchers in similar cases.
Sources
- decrypt.co — Core details of the impersonation scam, data exposed, and company response.
- coindesk.com — Confirmation of data types exposed and lack of funds lost.
How did this story land?
Choose one reaction. Choosing it again leaves it selected.
