Crypto news report · source clearly identified

Revolut Confirms Data Leak After Fake Government Email Request

Revolut says an external impersonation attack using a legitimate government domain led to the accidental transfer of customer documents, including passports and Bitcoin transaction records.

Revolut has confirmed that an unauthorised third party successfully tricked the company into sending sensitive customer files after receiving an email that appeared to come from a genuine government agency domain.

How the Attack Unfolded

The attacker used a legitimate government email address and valid domain credentials, causing Revolut’s systems to treat the request as authentic. The company says it blocked the sender as soon as the issue was identified.

Data Exposed

According to Revolut’s notice to affected users, the leaked information included:

  • Passports
  • Driving licences
  • Home addresses
  • Bank statements
  • Verification selfies (biometric facial data was not transferred)
  • A full record of Bitcoin deposits and withdrawals

Impact on Accounts

Revolut emphasizes that account security remains intact: login credentials, passcodes, and biometric authentication data were not compromised, and no funds were moved.

Response and Investigation

The firm reported the incident to the relevant government agency, law enforcement, and data‑protection and financial regulators. It has also contacted the limited number of customers affected. The specific government domain used has not been disclosed pending a police investigation.

Community Reaction

Blockchain investigator ZachXBT highlighted that the leak appeared to target a small group of users, possibly those with higher net worth. Users expressed concerns about the effectiveness of KYC processes after the breach.

Source & attribution

News Source

Publisher
BeInCrypto
Original date
September 12, 2026, 9:20 AM
Original headline
Revolut Confirms Fake Government Email Pulled Passports and Bitcoin Records: Who Sent It?
View original report ↗