Revolut Leaks Passports, BTC History to Fake Gov Request — SkimNews

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Revolut handed over sensitive customer data—including passport copies, verification selfies and full Bitcoin transaction histories—after fulfilling a request sent from an unauthorized email account using a legitimate government agency's official domain with valid domain authentication credentials.
- The exposed data spanned identity details (full name, date of birth, occupation), contact information, documents (passport or driver's license copies and verification selfies) and financial records including account statements with IBAN and wallet reference numbers; Revolut confirmed no biometric facial telemetry was involved.
- A Revolut spokesperson told TechCrunch it was "a sophisticated external impersonation scam," said a "limited" number of customers were affected, confirmed systems and customer funds were unaffected, blocked the email and alerted the agency, law enforcement and regulators—while declining to say how many people were hit or which agency was impersonated.
- ZachXBT circulated the customer notification and said the breach appeared to target high-net-worth users, raising "wrench attack" concerns given a surge in violent attacks against known crypto holders.
- Social media users, including Aave founder Marc Zeller, criticized the episode as evidence that KYC rules have created risk without meaningful benefit, with one telling Revolut: "Woke up to all my data leaked."
- The breach comes amid other recent crypto-data exposures: hardware wallet maker Trezor saw a support-vendor breach widen to expose tens of thousands more customers, while X appeared to suffer its own breach that flooded users with password resets.
- Revolut, which launched its euro-pegged EURR stablecoin this year, is currently weighing an IPO.
Why it matters: For the "limited" but high-net-worth crypto users whose passports and full Bitcoin histories landed in an impersonator's inbox, the exposure carries the wrench-attack risk that ZachXBT flagged is already surging—and Revolut, which is weighing an IPO, now holds the same KYC data that critics say created the vulnerability in the first place.
Ask SkimNews




