Revolut confirmed a fraudulent email sent from a legitimate government domain led to the release of customer passports, verification photos and Bitcoin transaction histories. The company says passwords, login credentials and biometric templates were not exposed and no funds were moved. Revolut blocked the sender and notified the relevant agency, police and regulators, but customer notices confirm photos and identity documents were released—raising risks of identity theft and targeted phishing. It remains unclear whether a government mailbox was hijacked or misused internally while police investigate.
Revolut Says Fake Government Email Prompted Release Of Passports, Verification Photos And Bitcoin Records

Revolut has confirmed it was tricked into disclosing customer files after responding to a fraudulent email sent from an address within a legitimate government agency domain. Company notices indicate the released material included passports, verification selfies and detailed Bitcoin transaction records for a limited number of users. Revolut maintains that account passwords, login credentials and stored biometric templates were not exposed and that no customer funds were moved.
What Happened
According to Revolut, the attack began with a single email that carried valid domain credentials tied to a real government agency. The message was accepted as authentic and a request for customer information was fulfilled. Revolut says it blocked the sender as soon as the issue was recognised and notified the relevant government agency, the police, its data protection regulator and financial regulators.
Revolut statement: "Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information... Revolut systems and customer funds are unaffected."
What Was Exposed
Customer notices list the specific items released: passports, driving licences, home addresses, bank statements and a complete record of Bitcoin movements for affected accounts. The notices also say verification selfies were disclosed but clarify that biometric facial templates (the mathematical face templates a system generates from an image) were not exposed. In practice, that means the photo itself may be available to the attacker even if the derived biometric template is not.
Revolut has declined to name which government domain was used, citing an ongoing police investigation. As a result, it is unclear whether an external actor hijacked a government mailbox or someone with access inside that mailbox sent the request.
Who Noticed And The Risks
Blockchain investigator ZachXBT flagged the leak and said it appears to have affected a small group of users, likely targeting wealthier customers. Stolen customer lists and exposed home addresses increase the risk of follow-on phishing campaigns and, in extreme cases, physical targeting of cryptocurrency holders.
Takeaways And Next Steps
Revolut says affected customers have been contacted. The firm emphasises that account logins and funds remain secure, but the release of identity documents and photos raises longer-term identity-theft and targeted-phishing concerns. The investigation by police is ongoing and Revolut continues to cooperate with authorities. Affected customers should monitor accounts, enable all available security protections, and consider identity-monitoring or fraud-alert services if sensitive documents were exposed.
Help us improve.




























