How did Revolut leak user passports and Bitcoin histories to a fake government request?

Revolut inadvertently disclosed sensitive user data, including passport scans and Bitcoin transaction histories, after fulfilling a fraudulent information request sent from a compromised government email domain. This breach highlights a significant vulnerability in fintech compliance departments where attackers leverage legitimate government infrastructure to bypass security protocols.
How did Revolut leak user passports and Bitcoin histories to a fake government request?

Revolut leaked private customer data by fulfilling a fraudulent information request that originated from a legitimate government agency's email domain. The fintech company admitted that it shared ID documents, such as passports, and full cryptocurrency transaction histories for a limited number of users after failing to identify the request as unauthorized. Because the email was sent using an official government domain, the request appeared authentic to Revolut’s compliance team, bypassing internal red flags.

The incident underscores a growing security threat in 2026 known as 'Government Email Compromise' (GEC). In this specific case, attackers did not need to hack Revolut’s internal servers; instead, they successfully compromised or spoofed the communications of a government body to exploit the legal obligation fintechs have to cooperate with law enforcement. This resulted in the unauthorized exposure of 'Know Your Customer' (KYC) data and granular Bitcoin movement records, which are often used by bad actors to target high-net-worth individuals for phishing or identity theft.

From a regulatory standpoint, this breach is likely to trigger investigations into whether Revolut maintained adequate 'zero-trust' protocols for Law Enforcement Request (LER) processing. As US and international regulators tighten data privacy laws in early 2026, fintech platforms are under increasing pressure to verify the identity of the requesting official through secondary, 'out-of-band' channels rather than relying solely on the authenticity of an email domain.

For crypto users, the immediate impact involves heightened security risks for those whose transaction histories were exposed, as their wallet addresses are now linked to their real-world identities in the hands of attackers. Investors should watch for updates from Revolut regarding credit monitoring services for those affected and potential industry-wide shifts toward decentralized identity solutions that could prevent such centralized points of failure in the future.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.