Meet the Top 101 in Crypto
Bitcoin (BTC)
4 min read

Revolut Fooled by Fake Government Request, Exposing Customer Passports and Bitcoin Records

Published 14 September 2026
Giuseppe Ciccomascolo
Authors

Key Takeaways

  • Revolut disclosed sensitive customer data after fraudulent information requests were sent from an email account on a legitimate government agency domain.
  • Potentially exposed records included passports, verification selfies, addresses, IBANs, and complete transaction histories, including Bitcoin activity.
  • Revolut says its systems were not breached and customer funds remain secure, but the incident raises questions over how financial firms authenticate government data requests.

Revolut has confirmed that it handed sensitive customer information to an unauthorized third party after being deceived by fraudulent requests that appeared to originate from a legitimate government agency.

The UK fintech said the attacker used an email account operating on an authentic government agency domain, allowing the requests to appear legitimate.

Revolut subsequently disclosed customer information before discovering that the requests were fraudulent, according to Reuters.

The company has not identified the government agency involved or disclosed exactly how many customers were affected. It described the incident as a “sophisticated external impersonation scam” affecting a limited number of customers and said its underlying systems were not compromised.

New Trending Crypto Wallet Offers
Sponsored
Disclosure
Opened in 2018
Promotions
Trusted, Secure & Crypto Friendly
Coins
Bitcoin Ethereum Tether Wrapped BNB USD Coin +87
Opened in 2017
Promotions
Receive Up to $10 in BTC when you buy and activate a Tangem Wallet.
Coins
Bitcoin Ethereum Tether Wrapped BNB Solana +68

Passports, Selfies, and Bitcoin Transactions Exposed

The scope of information potentially disclosed makes the incident particularly sensitive for cryptocurrency users.

Notifications sent to affected customers said the data could include names, dates of birth, occupations, postal and email addresses, and telephone numbers.

Copies of passports or driving licenses and facial verification images submitted during Know Your Customer checks were also potentially included.

Financial Information Went Considerably Further

Revolut said account statements, IBANs, account-opening dates, withdrawal records, and full transaction histories could have been disclosed, including records of Bitcoin transactions and wallet reference numbers.

Revolut stressed that passwords, passcodes, and customer funds were unaffected. The company also distinguished between verification selfies, which could have been disclosed, and biometric facial telemetry, which it said was not compromised.

Former Mt. Gox CEO Mark Karpelès said he was among those notified by Revolut. Onchain investigator ZachXBT also drew attention to the incident, suggesting that although the breach appeared limited in scale, it may have targeted high-net-worth customers. Revolut has not confirmed that assessment.

No Hack Was Needed to Get the Data

Unlike a conventional cyberattack, the incident did not require hackers to penetrate Revolut’s infrastructure.

The fraudulent communication originated from within a legitimate government domain and carried valid domain authentication credentials. Revolut therefore initially believed it was responding to an authentic government request.

That distinction highlights a different security weakness for banks and crypto platforms: attackers may not need to defeat a company’s technical defenses if they can successfully impersonate an organization that is legally entitled to request customer records.

Revolut’s own privacy policy states that it may share personal information with government agencies when legally required, underscoring why verifying such requests is critical to protecting customer data.

Revolut Alerts Regulators as Crypto Privacy Concerns Grow

Revolut said it blocked the unauthorized email address after identifying the problem and notified the affected government agency, law enforcement, data protection authorities, and financial regulators. Precautionary protections were also applied to affected accounts.

For Bitcoin holders, the combination of identity documents and financial history is potentially more concerning than either dataset alone.

Transaction records tied to a verified identity could provide attackers with information useful for highly targeted phishing or social-engineering attempts, although there is currently no evidence that affected customers’ crypto or fiat funds were stolen.

The unanswered questions are now likely to center on verification. Revolut has not revealed which government agency’s domain was abused, how the unauthorized account was created or compromised, or precisely how many customer records were released.

What is clear is that Revolut’s technology did not have to be hacked for highly sensitive financial information to leave the company. In this case, convincing the institution that the requester was the government was enough.

Disclaimer: The views, thoughts, and opinions expressed in the article belong solely to the author, and not necessarily to CCN, its management, employees, or affiliates. This content is for informational purposes only and should not be considered professional advice.
Giuseppe Ciccomascolo

Giuseppe Ciccomascolo began his career as an investigative journalist in Italy, where he contributed to both local and national newspapers, focusing on various financial sectors.

Upon relocating to London, he worked as an analyst for Fitch's CapitalStructure and later as a Senior Reporter for Alliance News. In 2017, Giuseppe transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies. He also played a pivotal role in establishing the academy for a cryptocurrency exchange website. Crypto remained his primary area of interest throughout his tenure as a writer for ThirdFloor.

Related

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status