Revolut Confirms Sending Passport and Bitcoin Records to Fake Government Email
Revolut has confirmed that fraudsters tricked the platform into handing over customer data, including information that its own notices say covered passports, verification selfies, and Bitcoin transaction records.
The request came from a real government agency email domain and carried valid credentials. Revolut believed it was genuine and released the data.
What Revolut Says Happened
A Revolut spokesperson told BeInCrypto the bank blocked the sender as soon as it spotted the problem.
“Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information… Revolut systems and customer funds are unaffected.”
The company says it alerted the agency, the police, and its data protection and financial regulators. It has contacted what it calls the limited number of people affected.
Are Revolut Accounts Secure?
Revolut says accounts remain secure. That is true. Passcodes, login details, and biometric data were never exposed, the bank told BeInCrypto. No money moved.
The notices sent to customers put it differently. They say the verification selfie went out, and rule out only biometric facial telemetry, meaning the face template a system builds from a photo. The photo itself is another matter.
Those notices list the rest. Passports, Driving licenses, Home addresses, Bank statements. A full record of Bitcoin going in and out.
Revolut will not say which agency’s domain was used, citing the live police investigation. So nobody outside the company knows whether a government mailbox was hijacked, or whether someone already inside it pressed send.
Blockchain investigator ZachXBT, who traces stolen crypto for a living, flagged the leak, highlighting that it reached a small group of users and looked aimed at wealthy ones.
Woke up to all my data leaked by @Revolut.
— Marc Zeller (@mzeller) September 12, 2026
Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way. pic.twitter.com/RimOBQr7DW
Stolen customer lists have fed phishing risk after breaches. Leaked home addresses have come before violent attacks on holders.
Revolut has described this as a sophisticated attack. But by its own account, the attacker used a legitimate government email system to send a fraudulent request. Revolut accepted that request as genuine and released the data.