Revolut handed over passport, address and Bitcoin records after mistaking a fake government request for a real one
Revolut has notified some customers that it disclosed personal and financial data after accepting what appeared to be a formal government information request that later turned out to have come from an unauthorized third party. The company said the request was sent from an unauthorized email account hosted within the infrastructure of a real government domain, allowing it to pass SPF, DKIM and DMARC checks. According to customer notices described in the report, the exposed data may include names, dates of birth, occupations, home addresses, email addresses, phone numbers, passport or driver’s license copies, selfie verification images, IBAN details, account status, account opening dates, wallet reference numbers, withdrawal records and full transaction histories, including Bitcoin transactions. As of Sept. 12, there was no public indication that Revolut’s systems had been breached, no evidence that passwords, card PINs or crypto private keys were stolen, and no public report that customer funds had been directly moved as a result of the incident. Revolut has not disclosed how many customers were affected or which government institution’s domain was abused.








