Revolut Allegedly Handed Over User Data Following a Forged Government Request
TREE NEWS reports: On-chain investigator ZachXBT has issued a warning that Revolut, the UK-based digital banking and crypto platform, appears to have mistakenly treated a fraudulent government information request as legitimate and provided partial user data to the requester. The compromised material reportedly includes identity and contact information, copies of identification documents, and verification selfies, with indications that high-net-worth users were specifically targeted.
The Mechanics of a Social-Engineering Attack
If confirmed, this incident represents a classic social-engineering breach rather than a technical exploit. Attackers impersonated a government authority to trigger a data disclosure process, and the platform’s internal verification controls failed to distinguish the forged request from a genuine legal order. For crypto-native users, the leak is especially dangerous: identity documents and selfies are the raw material for SIM-swap attacks, account takeovers, and targeted phishing that can drain exchange accounts and self-custody wallets alike.
Why High-Net-Worth Crypto Users Are Prime Targets
The reported focus on wealthy clients is telling. Crypto holders with large balances are attractive to organized crime because transactions are irreversible and assets can be moved across borders within minutes. A leaked passport scan paired with a phone number and email address gives attackers everything they need to impersonate a victim to a telecom provider or a customer-support desk. The combination of KYC data and crypto exposure creates a single point of failure that no hardware wallet can fully mitigate.
Regulatory and Industry Implications
- AML/KYC data custody is now a systemic risk. Centralized platforms hold vast honeypots of personal data. Regulators in the UK, EU, and US are likely to scrutinize how firms authenticate law-enforcement requests.
- Legal-request verification needs hardening. Platforms should adopt cryptographic verification, callback procedures, and multi-person approval for any disclosure of customer records.
- User liability questions will intensify. If a platform leaks data that leads to asset theft, the line between platform negligence and user responsibility will be tested in courts and by financial ombudsmen.
- Reputational damage could accelerate self-custody adoption. Incidents like this reinforce the argument that holding identity data at a centralized intermediary is itself a risk.
Forward-Looking Perspective
The crypto industry has spent years hardening private keys and smart contracts, yet the weakest link remains operational: a forged email or a phone call. Expect pressure on banks and exchanges to publish transparency reports on government data requests, adopt zero-knowledge or selective-disclosure identity systems, and insure against data-breach liability. For users, the practical takeaway is immediate: assume that KYC data held by any platform can eventually leak, enable hardware-based two-factor authentication, use dedicated phone numbers for financial accounts, and consider separating identity exposure from asset custody. Until legal-request verification becomes as rigorous as on-chain security, social engineering will remain one of the most profitable attack vectors in crypto.




