
UK fintech giant Revolut has admitted to handing over sensitive customer identities and complete Bitcoin transaction histories to scammers after being duped by a sophisticated government impersonation scam.
Fraudsters successfully exploited official email domain authentication to bypass standard compliance checks, tricking Revolut into releasing full Know Your Customer (KYC) packages and financial data under the guise of a lawful government request.
The incident bypasses traditional technical security defenses entirely, putting high-net-worth crypto holders at severe risk of targeted phishing, extortion, and social engineering attacks.
Unlike standard cyberattacks, the compromise did not involve a breach of Revolut’s core systems. Fraudsters submitted information demands using an email account hosted on a legitimate government agency domain.
Because the communications carried valid domain authentication credentials (passing SPF, DKIM, and DMARC checks), Revolut treated the requests as lawful law enforcement demands and fulfilled them before verifying their authenticity.
The exposed data is extensive and poses significant security risks for affected users. Notifications sent to impacted customers revealed that the disclosed information includes:
Revolut clarified that passwords, passcodes, card PINs, crypto private keys, and customer funds were not compromised, nor was raw biometric facial telemetry shared.
On-chain investigator ZachXBT and former Mt. Gox CEO Mark Karpelès highlighted the breach, with ZachXBT noting that the targeted campaign appeared focused on high-net-worth users.
Crypto industry figures voiced frustration over mandatory KYC data collection, noting that linking real-world identities and home addresses to Bitcoin holdings poses severe risks of targeted phishing or physical extortion attacks.
Revolut blocked the sender address, contacted the affected government agency, and notified law enforcement, data protection authorities, and financial regulators.
The firm stated that a “limited number” of users were impacted, but has so far withheld the total count of affected accounts and the name of the impersonated government agency, citing an ongoing investigation.
Check your email to confirm
We sent a confirmation link to . Confirm it to activate your Kyroo cashback — you can do this anytime.
You're in! Taking you to {partner} in ...