The Fake Government Request
Digital bank Revolut fell victim to a social-engineering scheme in which a fraudulent request, styled to resemble an official government inquiry, was accepted as legitimate. The bank's internal processes failed to flag the impersonation, and staff processed the request as though it had come from a verified public authority. The result was an unauthorized disclosure of sensitive customer data spanning multiple categories of personal information.
What Was Leaked
According to the reporting, the data handed over included customers' Bitcoin activity records, passport images, selfie verification photos, and residential addresses. The breadth of the disclosure is notable: it combined financial transaction history with government-issued identity documents and biometric-style verification images, creating a package that could be exploited for identity fraud, targeted phishing, or cryptocurrency-related social engineering attacks.
Importantly, the incident did not result in the loss of any customer funds. The perpetrators accessed records and documents but did not move or drain balances from Revolut accounts.
Scam Alert for Traders and Crypto Holders
For forex and cryptocurrency traders, this incident underscores several risk factors worth monitoring:
- Identity documents as a target. Passports and verification selfies are high-value items on the black market. If your identity documents have been exposed through a financial institution, remain vigilant for phishing emails or phone calls that reference your specific account details.
- Crypto transaction history as leverage. Exposed Bitcoin activity gives fraudsters a precise map of your holdings, exchange preferences, and timing. This can be used to craft convincing impersonation scams or to target you in fake support calls.
- Institutional due diligence is not guaranteed. Even regulated digital banks can be tricked by well-crafted government-style requests. Traders should not assume that their custodian's internal processes are impervious to social engineering.
We recommend that any Revolut customer affected by this disclosure monitor their credit reports, enable multi-factor authentication on all financial and exchange accounts, and report any suspicious contact referencing their personal or transaction data to relevant fraud authorities.
No further details regarding the scope of affected customers, the timing of the breach, or the identity of the perpetrators have been confirmed in the available reporting.