Fake Gov Email Just Stole Revolut Users' Passports and Bitcoin Records: Nobody Knows Who Sent It
Someone impersonated a government authority, sent a single email, and walked away with Revolut customer passports and Bitcoin transaction records — and the company still cannot confirm who did it.
Revolut, one of Europe's largest fintech platforms with over 50 million users, has confirmed that a fraudulent legal request, disguised as an official government communication, successfully bypassed its data-handling process and extracted sensitive customer information. That data includes identity documents and cryptocurrency transaction history.
How a Fake Email Beat a $45B Fintech's Security
This is not a hack in the traditional sense. No firewall was breached. No zero-day exploit was used. Someone crafted a convincing government-style legal demand, sent it to Revolut's compliance or legal team, and the data was handed over voluntarily, because staff believed the request was legitimate.
This type of attack is known as a fraudulent legal process exploit, and it is alarmingly effective. Compliance teams inside financial institutions are trained to respond quickly to government data requests. That urgency is exactly what the attacker weaponized.
The fact that Bitcoin records were specifically included in the pulled data raises serious questions. Was this a targeted operation aimed at identifying crypto holders? Was it financially motivated, seeking wallet sizes or transaction patterns to enable follow-on attacks? Or was it a state-level intelligence operation using a spoofed identity?
Revolut has not answered any of those questions publicly. The sender remains unidentified.
Why Crypto Holders Should Care Right Now
If you hold Bitcoin or any crypto asset through Revolut, your transaction history and identity documents may now be in unknown hands. This is not a hypothetical risk. The data was confirmed extracted.
This incident exposes a critical and underappreciated attack surface across the entire fintech and crypto industry. Exchanges, neobanks, and custodians all receive legal data requests regularly. Most have compliance processes that assume the requesting party is legitimate. That assumption is now a documented liability.
The implications go further. As crypto adoption scales and more users store assets through regulated platforms, bad actors have a clear incentive to target the legal and compliance layer rather than the technical one. It is cheaper, faster, and apparently effective.
What You Should Watch and Do
Revolut users should monitor official communications closely for any breach notification and consider whether sensitive crypto activity belongs on a centralized, regulated platform with this kind of exposure. The broader market should watch for whether regulators respond with stricter verification standards for data requests.
The identity of the sender is the story. Until that is resolved, no Revolut customer with crypto holdings should assume their data is safe.