Revolut Customers Exposed by Fake Government Request
A recent incident at Revolut exposed sensitive customer data after a fake government request was made to the financial institution. According to on-chain investigator ZachXBT, a subset of Revolut customers had their passports, verification selfies, full transaction histories, and home addresses compromised.
The breach occurred due to a fraudulent request that slipped through the company's verification layer, which is designed to prevent unauthorized access to customer data. This distinction is significant because it means someone impersonated a government authority convincingly enough to obtain sensitive information from Revolut without being detected.
Affected users had copies of their passports and driver's licenses exposed, along with account statements, IBAN details, withdrawal records, and full transaction history, including Bitcoin activity. The combination of this data creates a complete picture that can be used for identity theft or impersonation scams.