BNB $736.17 +0.37%
XRP $1.37 -2.55%
ETH $2,541.83 -2.59%
BTC $77,364.87 -2.09%
BNB $736.17 +0.37%
XRP $1.37 -2.55%
ETH $2,541.83 -2.59%
BTC $77,364.87 -2.09%
BREAKING
Bitcoin News

Revolut Exposes Sensitive Bitcoin Data and Passports After Falling for Fake Inquiry

Revolut Hands Over Bitcoin Data and Passports After Fake Government Request Slips Through
Revolut Hands Over Bitcoin Data and Passports After Fake Government Request Slips Through

Community Trust ScoreVerified

83%
Real
Verified24 votes
Updated 30 minutes ago

Revolut got played. The digital banking giant accidentally handed over sensitive customer data — Bitcoin transaction records, passport scans, selfies, home addresses — after treating a fake government inquiry like the real thing.

It’s a bad look. The breach didn’t drain any accounts, Revolut confirmed that much, but the personal data exposure is serious enough on its own. Passports. Selfies. Home addresses. Bitcoin transaction histories. All of it went out the door because someone inside the company’s compliance chain didn’t catch that the request was bogus. No funds lost, sure — but the kind of data that got out can do plenty of damage without touching a bank balance.

What Actually Got Exposed

The data package Revolut sent out was pretty comprehensive, and not in a good way. Bitcoin transaction details were part of it, which matters a lot for crypto holders who reasonably expect their financial activity to stay private. Add in government-ID documents, facial images, and physical addresses, and you’ve got a near-complete dossier on whoever was caught up in this. Revolut hasn’t said how many customers were affected. That number is still unclear, and the company is still working through the full scope of what went out and to whom.

Advertisement

What’s also unclear is which government agency the fake request claimed to be from. Revolut hasn’t named the entity. It hasn’t explained how the fraudulent inquiry was formatted, whether it carried forged signatures or official-looking letterheads, or why it passed internal checks. Those details matter enormously for understanding how bad the security gap actually is — and right now, the company isn’t saying.

No timeline for finishing the internal investigation has been given either.

Revolut’s Response So Far

The company launched an internal investigation after the breach came to light. It’s also working with cybersecurity experts to figure out exactly how the fake request slipped past existing protocols, though no preliminary findings have been shared publicly. Revolut says it’s cooperating with relevant authorities on any regulatory concerns that might follow, but it hasn’t specified which regulators are involved or what those conversations look like.

Affected customers are being notified — that part is happening. But the guidance being offered is vague. Revolut is telling people to take precautionary steps to protect their personal information without spelling out what those steps actually are. No detailed individual action plan has been sent out yet. Customers are basically being told to stay cautious and wait for more.

And that’s probably the most frustrating part of how Revolut has handled the public-facing side of this. The company keeps saying further updates are coming as the investigation progresses, but the specifics are thin. No timeline. No named regulators. No count of affected users. No explanation of how the fraudulent request was constructed or why it worked.

Bigger Questions for Digital Banking

The attack that caught Revolut out is a form of social engineering — fake legal or government requests designed to trick companies into handing over data they’d normally protect. It’s not new. Financial institutions and tech platforms have faced versions of this for years, and the crypto-adjacent angle makes it worse. Bitcoin transaction data is particularly sensitive because it can be used to map a person’s financial behavior, identify wallet addresses, and potentially expose them to targeted fraud or theft.

Revolut is under real pressure now to show it can fix the verification gap that made this possible. The company says strengthening its request-verification processes is the priority, but it hasn’t outlined specific enhancements. That’s a problem. Vague assurances don’t rebuild trust after a breach like this, and regulators watching from the sidelines aren’t going to be satisfied with “we’re working on it” for long.

The digital banking sector broadly is probably going to feel some secondary pressure from this. When one major platform gets caught out by a fake government request, compliance teams across the industry start asking whether their own procedures would hold up to the same kind of attack. Probably some won’t.

Revolut’s failure here wasn’t a technical hack in the traditional sense — no system was cracked, no malware deployed. Someone just asked for data using a convincing-enough fake, and Revolut gave it. That’s a process failure, a human failure, and maybe a training failure. It’s also the kind of failure that’s genuinely hard to defend against at scale, because the volume of legitimate government requests that a platform like Revolut handles is enormous, and bad actors know that.

The company hasn’t clarified whether the entity behind the fake request has been identified or whether law enforcement is actively pursuing the case. Customers affected by the breach are advised to monitor their accounts and personal information closely. Revolut says no financial losses have been reported.

Frequently Asked Questions

What customer data did Revolut expose in the breach?

Revolut handed over Bitcoin transaction details, passport scans, selfies, and home addresses after mistaking a fake government request for a legitimate one.

Were Revolut customer funds stolen or lost in the incident?

No. Revolut confirmed that customer funds remained secure and unaffected, though personal data exposure remains a serious concern for those impacted.

Why It Matters

This incident underscores the vulnerabilities that digital financial platforms face in safeguarding sensitive customer data, which can erode trust and lead to regulatory scrutiny. As the cryptocurrency market matures, such breaches may prompt tighter regulations and compliance requirements, influencing operational practices across the industry. The exposure of personal information, particularly in the context of cryptocurrency, raises concerns about privacy and the potential for identity theft, which could deter users from engaging with digital banking services.

Community Trust IndexHigh Confidence
83%
Real
Real83%17%Fake
24 community signals

Dan Saada

Dan Saada holds a Master of Finance from ISEG Business School (France). With years of experience covering digital assets, Dan specializes in cryptocurrency market analysis, blockchain technology, and decentralized finance.

Advertisement

Related Stories