Crypto news report · source clearly identified
Revolut mistakenly released passports and Bitcoin histories after fraudulent government request
Revolut disclosed customers’ passports, verification selfies and Bitcoin transaction histories after treating a fraudulent government request as legitimate. Affected customers were told Friday that the disclosed information could include passport or driver’s license copies, verification selfies, names, dates of birth, occupations, home addresses, phone numbers, IBANs, and account statements.

Revolut has confirmed that it unintentionally shared sensitive personal documents and cryptocurrency transaction records with an attacker after responding to a fraudulent request that appeared to originate from a legitimate government agency.
How the breach occurred
The request arrived from an unauthorized mailbox within the email infrastructure of a genuine government entity and carried valid authentication credentials, passing SPF, DKIM and DMARC checks. Believing the email to be authentic, Revolut complied with the request and provided copies of passports or driver’s licenses, verification selfies, personal details (name, date of birth, occupation, home address, phone number), IBANs, account statements, and full Bitcoin withdrawal and transaction histories.
Discovery and response
After contacting the agency separately, Revolut learned the request was fraudulent, blocked the offending email address, and began notifying affected customers and regulators. The company has not disclosed the identity of the government agency involved or the exact number of customers impacted.
Potential impact
- No funds or private keys were reported stolen.
- Exposed data includes identity documents, contact information, residential addresses, and detailed cryptocurrency activity.
- Linking verified identities to on‑chain Bitcoin activity could enable attackers to map broader on‑chain behavior.
Industry reaction
Marc Zeller, founder of the Aave Chan Initiative, criticized Revolut for demanding extensive data from him shortly before the breach, suggesting the company effectively performed the attackers’ work. On‑chain analyst ZachXBT noted the incident appears limited to high‑net‑worth customers, though Revolut has not provided a scope figure.
Broader implications
The incident highlights challenges fintech firms face in verifying government information requests, especially when attackers gain access to legitimate email accounts. It raises questions about the adequacy of current verification processes and the risks of aggregating extensive identity and transaction data for compliance purposes.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- September 12, 2026, 3:30 PM
- Original headline
- Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers