Crypto

Revolut Exposed Bitcoin Histories After Fake Government Data Request

A fake law enforcement request accessed crypto clients’ identity and transaction records

Revolut surrendered sensitive personal documents and complete Bitcoin transaction histories belonging to high-net-worth cryptocurrency clients after cybercriminals exploited weaknesses in legal data-request procedures. The London-headquartered digital financial services provider said the incident involved a “sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”

The unauthorized request came from an official email domain belonging to a government agency. Because the domain was legitimate and used valid authentication protocols, including Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM), Revolut’s compliance mechanisms processed the inquiry as an authentic law enforcement request.

The company has not identified the government agency whose email domain was compromised and declined to state how many victims were affected, saying only that a “limited” number of accounts were involved. Revolut blocked the fraudulent email address, notified the impersonated agency, and reported the breach to relevant law enforcement authorities and financial regulators. Its internal core systems, databases, and customer financial balances remained secure and unaffected.

Pseudonymous blockchain investigator ZachXBT brought the incident to public attention by publishing copies of breach notification letters sent by Revolut to affected users. The disclosures said the exposed records included full legal names, dates of birth, registered occupations, residential addresses, primary email addresses, and phone numbers. Government identity credentials were also included, such as photographic copies of passports or driver’s licenses and self-portrait verification photos submitted during account opening.

The files contained financial records including International Bank Account Numbers (IBANs), digital wallet reference identifiers, fiat transaction histories, and full logs of cryptocurrency transfers. The cryptocurrency records specifically detailed Bitcoin account activity. Revolut confirmed that biometric facial telemetry data was not included in the surrendered files.

The incident is an example of Emergency Data Request (EDR) fraud, in which attackers gain access to compromised law enforcement email accounts or domain servers. They then submit urgent requests for customer records while posing as government investigators, bypassing formal judicial review, subpoenas, and international legal treaties. Similar domain-impersonation tactics have previously compromised user data at Apple, Meta, Snap, and Discord.

ZachXBT said the compromised accounts appeared to selectively target high-net-worth individuals. The combination of home addresses and explicit Bitcoin transaction amounts has renewed concerns over the physical security of digital asset holders. It has also raised alarms about potential “wrench attacks,” a term for violent home invasions, physical extortions, or abductions intended to force people to surrender private keys or access credentials to cryptocurrency reserves.

Privacy advocates and financial industry commentators have used the breach to renew criticism of mandatory Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements imposed under regulations associated with bodies such as the Financial Action Task Force (FATF). Global regulatory guidelines require institutions to retain sensitive personal identification records for years. Critics argue that collecting and storing unencrypted physical identity documents creates centralized databases that become prime targets for cybercriminals.

Revolut was founded in 2015 by Nikolay Storonsky and Vlad Yatsenko and has grown into Europe’s most valuable private technology business. Its valuation reached $45 billion after an employee share sale in August 2024, while the company secured a UK banking license with restrictions from the Prudential Regulation Authority (PRA) in July 2024. Revolut is also preparing for an initial public offering (IPO).

Earlier this year, Revolut expanded its cryptocurrency ecosystem by launching EURR, a euro-pegged stablecoin compliant with the European Union’s Markets in Crypto-Assets (MiCA) framework. The breach occurred amid a broader surge in digital asset industry data exposures: hardware wallet vendor Trezor said a compromise involving a third-party customer support software supplier affected tens of thousands of additional users and exposed email addresses and contact records. Separately, social media platform X experienced technical security disruptions that caused widespread unauthorized password reset notifications to be sent to users.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *