Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: revolut (1 article)Clear

Revolut handed customer passports and crypto histories to a fake government email

Fintech Revolut disclosed that it released sensitive customer data to attackers who sent a fraudulent information request from an email account operating inside a real government agency's domain. Because the message passed standard email-authentication checks, Revolut treated it as a genuine legal or government request and complied. The exposed data for a limited number of users included passport or driver's license copies, verification selfies, full identity and contact details, and complete transaction histories including Bitcoin activity. It was not a breach of Revolut's systems but an abuse of the trusted legal-request process. The combined identity and financial data enables convincing impersonation, SIM-swapping, and targeted attacks on cryptocurrency holders.

Check
Organizations that fulfill legal or government data requests should verify them out of band through a known contact, not just by trusting domain authentication, since a spoofed mailbox can pass those checks.
Affected
A limited number of Revolut customers whose passports, selfies, identity details, and Bitcoin transaction histories were exposed; the combined data supports impersonation, SIM-swapping, and fraud, and identity documents cannot be reissued.
Fix
Build out-of-band verification into legal and law-enforcement data-request handling, limit what any single request returns, log and review disclosures, and warn affected customers about impersonation and crypto-targeted scams.