Bitcoin · CoinDesk
Bitcoin activity, passports exposed after Revolut falls for fake government request
Compiled by KHAO Editorial — aggregated from 3 sources. See llms.txt for citation guidance.
✓ KHAO Verified
A fake government email slipped through security controls at digital banking giant Revolut this week, exposing residential addresses, identity documents and bitcoin transaction histories belonging to a wide group of customers.
Key facts
- The request appeared to come from a legitimate government agency and carried credentials that passed Revolut’s checks
- Revolut has yet to disclose how many customers were affected, and did not immediately respond to a CoinDesk request for comment on the matter
- It said in its email that customer funds remained safe and has since notified affected users and regulators and blocked the source of the request
- The breach also gives privacy technologies such as zero-knowledge proofs a more immediate use case
Summary
Revolut disclosed customers’ identity documents, residential addresses and transaction histories after a fraudulent government request passed its security checks. The company said customer funds remained safe, but it has not disclosed how many users were affected; the breach may have targeted high-net-worth customers. The incident highlights how AI-assisted impersonation can exploit authorization systems and strengthens the case for privacy tools that let institutions verify customers while retaining less sensitive data. The request appeared to come from a legitimate government agency and carried credentials that passed Revolut’s checks.