Revolut leaked passports and Bitcoin histories after fake government request
Revolut gave away ID documents and crypto transaction data after falling for a spoofed government request, exposing security gaps for fintech users.

According to Decrypt, Revolut complied with a request that appeared to come from a government agency, sending passport scans and full Bitcoin transaction histories for a limited set of customers. The breach shows how a single forged email can force a major fintech into handing over sensitive personal and financial data, raising questions about verification procedures in an industry that markets itself as secure.
What happened
Revolut’s compliance team received an email that used the official domain of a national tax authority. The message asked for “identity verification documents” and “crypto transaction records” for a handful of users. Believing the request genuine, Revolut’s staff exported passport images and the complete Bitcoin activity linked to the accounts, then transmitted the files to the sender. The data dump included scanned passports, dates of birth, and every Bitcoin address the affected users had ever used on the platform, along with timestamps and amounts of each transaction. The breach affected a “limited” number of accounts, but the exact count was not disclosed.
Why it works that way
Fintech companies like Revolut operate under a regulatory framework that obliges them to cooperate with lawful government requests. When an authority needs information, it typically sends a formal request, often through a secure channel, and the company must verify the request before releasing data. In practice, many compliance teams rely on visual cues—such as the sender’s email domain and the wording of the request—to confirm authenticity. Phishing attacks exploit this reliance by mimicking official domains, crafting emails that look identical to genuine communications, and using language that mirrors legal terminology. Because the request came from a domain that matched the real tax authority, the compliance officer likely assumed it passed the verification step.
The underlying mechanism is simple: a request triggers a workflow that pulls data from internal databases and formats it for delivery. If the trigger is accepted without a second‑factor check—like a phone call to a known contact at the agency or a verification code sent through a separate channel—there is no safeguard against a spoofed email. Revolut’s internal policy apparently did not require such a dual verification, allowing the fake request to move straight to data extraction.
What changes because of it
The immediate fallout is the exposure of personal identification and detailed crypto transaction histories. Passports link a user’s real‑world identity to their on‑chain activity, making it easier for criminals to target them for extortion or blackmail. The transaction data also reveals spending patterns, entry and exit points, and potentially the size of a user’s holdings, which could be leveraged in phishing or social engineering attacks.
For Revolut, the breach forces a review of its compliance processes. The most obvious change will be adding a mandatory secondary verification step for any request that involves identity documents or crypto data. This could mean phone‑based confirmation with a known government liaison, or using a secure portal where agencies upload signed requests that can be cryptographically validated. Implementing such checks would slow down the response time for legitimate investigations but would dramatically reduce the attack surface for spoofed requests.
Customers who hold Bitcoin on Revolut now have a reason to reconsider where they keep their assets. The platform’s convenience—instant buying, selling, and storage—has always been balanced against the fact that users do not control the private keys to their coins. In practice, this means Revolut can see every transaction and, as shown here, can hand that data over if it believes a request is valid. Users who value privacy may shift to self‑custody wallets, where only they possess the keys and can control which data leaves their device.
Regulators may also look more closely at how fintechs verify government requests. The breach highlights a gap in the current oversight model, where the burden of verification sits entirely on the company. Future guidance could require documented dual‑auth processes, audit trails of request handling, and periodic third‑party assessments of compliance workflows.
From a broader perspective, the incident underscores the tension between regulatory cooperation and user privacy in the crypto space. While governments need access to transaction data for anti‑money‑laundering (AML) and tax purposes, the method of obtaining that data must be robust against social engineering. The trade‑off here is speed versus security: faster compliance helps law‑enforcement but opens a door for attackers. In practice, the balance will tilt toward stricter verification once the reputational damage of incidents like this outweighs the inconvenience of a longer response time.
What to watch next: whether Revolut publicly outlines new verification steps, how quickly they roll out any changes, and whether other fintechs announce similar policy upgrades. Watch for statements from the tax authority involved—if they confirm the spoof, it may trigger a wider alert to other financial institutions. Finally, keep an eye on user migration trends; a noticeable shift from custodial platforms to non‑custodial wallets would signal that privacy concerns are reshaping where people store their crypto.


