Revolut data breach exposes Bitcoin transaction records
Revolut exposed customer identity and Bitcoin transaction data after falling for a fake government request. No funds or biometric data were compromised, but sensitive records were disclosed.
Recent reports reveal that Revolut inadvertently exposed sensitive customer data, including identity documents, verification selfies, home addresses, and Bitcoin transaction histories. This occurred after the company responded to a fraudulent request that convincingly impersonated a government agency using a real agency email domain and passing authentication checks. The breach did not involve hacking accounts or compromising passwords, private keys, or customer funds. Instead, it exploited weaknesses in Revolut’s process for verifying official data requests. The incident appears to have affected a limited number of users, possibly targeting high-net-worth individuals. Impacted customers have been notified. Revolut has informed authorities and regulators, emphasizing that biometric data and customer funds were not exposed. The event underscores the risks of sophisticated impersonation attacks and highlights the need for stronger verification procedures when handling sensitive legal requests.