Revolut Confirms Data Handed to Impersonated Government Address
TREE NEWS reports: Revolut has confirmed that it disclosed customer data — including passport scans and Bitcoin transaction records — to an email address impersonating a government authority. The disclosure marks one of the more unusual social-engineering breaches to hit a major fintech-crypto hybrid, and it raises uncomfortable questions about how regulated firms verify inbound legal requests.
What Happened
The neobank, which offers crypto trading to millions of retail users across Europe and the UK, acknowledged that a spoofed government email successfully triggered a data transfer. The records involved identity documents and digital-asset activity, a combination that is particularly sensitive because it links a verified legal identity to a specific on-chain history.
Why This Matters for the Crypto Industry
This is not a smart-contract exploit or a bridge hack. It is a process failure at the boundary between traditional finance compliance and crypto data. That boundary is precisely where the industry is most exposed right now.
- KYC data is the new honeypot. Exchanges and fintechs hold passport scans, selfies, addresses and wallet histories. A single successful impersonation can deanonymize users who assumed their on-chain activity was pseudonymous.
- Law-enforcement request handling is a weak link. Firms face pressure to respond quickly to subpoenas and information requests. Attackers exploit that urgency with forged domains and official-sounding language.
- Regulatory convergence raises the stakes. As frameworks such as MiCA and evolving AML rules push more identity collection onto crypto platforms, the volume of sensitive data at risk grows with every new compliance requirement.
The Broader Pattern
Social engineering against compliance teams has become a recurring theme. Attackers rarely need to break encryption when they can simply ask for the data in the right tone of voice, from the right-looking domain. For crypto firms, the reputational damage is amplified because users specifically chose these platforms partly to limit exposure of their financial identity.
What Comes Next
Expect renewed scrutiny of how crypto-facing firms authenticate inbound government requests. Reasonable responses include:
- Mandatory out-of-band verification — callback to a known official number — before any data release.
- Cryptographically signed request channels for law enforcement and regulators.
- Stricter internal logging and dual-authorization for identity-document transfers.
- Clearer disclosure obligations to affected users when data is mistakenly released.
The incident is a reminder that in crypto, operational security and compliance are not separate disciplines. The same users who worry about seed-phrase hygiene should also ask how their exchange verifies the people demanding their passports. Until that question has a robust answer across the industry, identity data will remain the softest target in the ecosystem.




