Bitcoin activity, passports exposed after Revolut falls for fake government request

Revolut suffered a significant data breach after falling for a fraudulent government request that bypassed its internal verification systems. The exposed data includes highly sensitive personal information, such as passport details, transaction histories, and bitcoin activity, highlighting the growing risks of AI-enabled impersonation in financial services.
Why it matters
This incident underscores the urgent need for privacy-preserving technologies like zero-knowledge proofs as AI makes traditional identity verification methods increasingly vulnerable to sophisticated social engineering.
The request appeared to come from a legitimate government agency and carried credentials that passed Revolut’s checks. The company handed over customer information before separately contacting the agency and discovering that the request was fraudulent, according to notices sent to affected users.
The files reportedly included passports or driving licences, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs, account statements, withdrawal records and full transaction histories, including all bitcoin activity.
Revolut has yet to disclose how many customers were affected, and did not immediately respond to a CoinDesk request for comment on the matter.
it said in its email that customer funds remained safe and has since notified affected users and regulators and blocked the source of the request.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in