On-chain investigator ZachXBT revealed earlier today that Revolut had disclosed highly sensitive personal and financial information belonging to certain customers after receiving what appeared to be an authentic government request.

The company sent emails to the affected users, admitting that the exposed records included passports, verification selfies, addresses, and complete Bitcoin transaction history.

What Was Exposed

In the email sent to customers and revealed by ZachXBT on his Telegram page, Revolut explained that it received a request for information that appeared to originate from a legitimate government agency. The sender was not merely spoofing an address that looked official. The request came from an unauthorized email account using the government agency’s actual email domain and carried valid domain authentication credentials, the company added.

Revolut fulfilled the request under the belief that it was legit. The disclosed information potentially included certain customers’ full names, dates of birth, occupations, home addresses, email addresses, and phone numbers. More sensitive material included copies of passports and/or driver’s licenses and the selfie images clients had supplied during the verification process. The good news, according to the company, is that biometric facial telemetry itself was not compromised.

However, the firm said it has provided financial information, including account statements containing IBANs, account-opening dates and wallet reference numbers, as well as withdrawal records and full transaction history, including BTC transactions.

So far, Revolut has not publicly named the government agency involved, and the notice sent to customers does not indicate whether passwords, private keys, or their funds were accessed.

Going Against the Rich?

The on-chain sleuth described the incident as “likely limited in size,” as it seemed that the perpetrators focused only on high-net-worth users. However, this hasn’t been confirmed either independently or by Revolut itself. In addition, the company hasn’t disclosed the actual number of affected clients.

Given the available information as of press time, the incident appears to be an unauthorized disclosure rather than a direct compromise of Revolut’s infrastructure. The company itself instructs government and law-enforcement bodies to submit official information requests through a dedicated channel.

The post Revolut Exposed Passports and Bitcoin Records After Fake Government Request: Report appeared first on CryptoPotato.