Revolut: Fake government email exposed passports, Bitcoin records

Revolut confirmed a fraudulent email from a legitimate government domain led it to release customer files including passports, verification selfies and Bitcoin transaction records.

Revolut confirmed that a fraudulent email sent from a genuine government agency domain prompted the company to release customer files that included passports, verification selfies and records of Bitcoin transactions. The incident was identified recently and described as a sophisticated external impersonation attack.

The company blocked the sender as soon as it spotted the message and alerted the relevant government agency, the police, and data protection and financial regulators. Revolut contacted a limited number of affected customers and said customer accounts and funds were not accessed or moved.

In a statement, Revolut said: “Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information… Revolut systems and customer funds are unaffected.”

The company added that login passcodes, account credentials and biometric templates used for facial recognition were not exposed. Customer notices list the material that was released: passports, driving licences, home addresses, bank statements, verification selfie images and full records of Bitcoin transactions. The notices indicate the selfie images were provided while the underlying facial telemetry used for automated verification was not.

According to Revolut, the attacker used an email that came from a genuine government domain and carried valid domain credentials, which led staff to accept the request as authentic. The firm has not named the agency, citing an ongoing police investigation, so it is unclear whether a mailbox was hijacked or an insider at the agency sent the message.

A blockchain investigator who traces stolen crypto flagged the disclosure, noting it reached a small group of customers and appeared to target wealthier account holders. Security specialists say leaked personal data and contact details can increase the risk of phishing and other follow-on attacks; leaked home addresses have been linked to physical threats against holders of digital assets in prior incidents.

Revolut declined to disclose how many customers were affected. The company says it has taken steps to limit further exposure by blocking the sender, notifying authorities and regulators, and contacting impacted customers. The police investigation is ongoing.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author