TREE NEWS update: Revolut fulfilled a fraudulent information request sent from a government agency’s own email domain, exposing ID documents and full crypto transaction histories for a limited number of users. The fintech company said the breach affected only a limited number of users, and the incident involved passports and complete Bitcoin transaction histories.
Revolut Leaks Passports and Bitcoin Transaction Histories to Fake Government Request
The notable part is the vector: a forged request from a genuine government domain, which turns institutional trust in official email into an attack surface rather than a technical exploit. For crypto users, the exposure is unusually deep — identity documents paired with complete transaction histories create a link between a legal name and on-chain activity that persists regardless of wallet hygiene. Whether such domain-spoofed requests become a recurring pattern across regulated platforms is the open question worth watching.
Generated by AI for reference only.
Share on WeChat
Open WeChat → Scan → then tap "…" to send to a chat or Moments.
Tap "…" in the top-right corner to send to a chat or share to Moments.