Home / News / Revolut Shared Customer KYC and Bitcoin Transaction Data With Fraudsters in Government Impersonation Scam
News 3 min read

Revolut Shared Customer KYC and Bitcoin Transaction Data With Fraudsters in Government Impersonation Scam

Verified by Ed Acteson
Revolut Shared Customer KYC and Bitcoin Transaction Data
Revolut Shared Customer KYC and Bitcoin Transaction Data

Key Takeaways

  • Revolut’s internal infrastructure, servers, and databases were never hacked or compromised.
  • The event was carried out exclusively through an external impersonation scam targeting Revolut’s compliance team.
  • Scammers sent requests directly from an email address hosted on a legitimate government agency domain.
  • Revolut fulfilled the data request on the belief that it was a lawful law enforcement request.

UK fintech giant Revolut has admitted to handing over sensitive customer identities and complete Bitcoin transaction histories to scammers after being duped by a sophisticated government impersonation scam.

Fraudsters successfully exploited official email domain authentication to bypass standard compliance checks, tricking Revolut into releasing full Know Your Customer (KYC) packages and financial data under the guise of a lawful government request.

The incident bypasses traditional technical security defenses entirely, putting high-net-worth crypto holders at severe risk of targeted phishing, extortion, and social engineering attacks.

Valid Domain Tricked Authentication

Unlike standard cyberattacks, the compromise did not involve a breach of Revolut’s core systems. Fraudsters submitted information demands using an email account hosted on a legitimate government agency domain.

Because the communications carried valid domain authentication credentials (passing SPF, DKIM, and DMARC checks), Revolut treated the requests as lawful law enforcement demands and fulfilled them before verifying their authenticity.

Sensitive Identity and Bitcoin Records Disclosed

The exposed data is extensive and poses significant security risks for affected users. Notifications sent to impacted customers revealed that the disclosed information includes:

  • Personal identity details: Full names, dates of birth, occupations, physical addresses, phone numbers, and email addresses.
  • KYC documentation: Copies of passports or driver’s licenses and onboarding verification selfies.
  • Financial & crypto data: Account statements, IBANs, withdrawal logs, wallet reference numbers, and complete transaction histories detailing Bitcoin activity.

Revolut clarified that passwords, passcodes, card PINs, crypto private keys, and customer funds were not compromised, nor was raw biometric facial telemetry shared.

Scope and Industry Reaction

On-chain investigator ZachXBT and former Mt. Gox CEO Mark Karpelès highlighted the breach, with ZachXBT noting that the targeted campaign appeared focused on high-net-worth users.

Crypto industry figures voiced frustration over mandatory KYC data collection, noting that linking real-world identities and home addresses to Bitcoin holdings poses severe risks of targeted phishing or physical extortion attacks.

Revolut blocked the sender address, contacted the affected government agency, and notified law enforcement, data protection authorities, and financial regulators.

The firm stated that a “limited number” of users were impacted, but has so far withheld the total count of affected accounts and the name of the impersonated government agency, citing an ongoing investigation.

Was this Article helpful? Yes No
Thank you for your feedback. 0% 0%