Revolut Confirms Fake Government Email Pulled Passports And Bitcoin Records: Who Sent It?
- The message arrived from a real government agency’s email domain.
- Revolut accepted it as authentic and sent the files.
- A Revolut spokesperson told BeInCrypto the bank blocked the sender as soon as it spotted the problem.
- Follow us on X to get the latest news as it happens
What Happened
Revolut has confirmed to BeInCrypto that someone did actually trick it into handing over customer files, which its own notices say held passports, selfies, and Bitcoin records. The company calls it a sophisticated attack. What it describes is an email.
The message arrived from a real government agency’s email domain. It carried genuine domain credentials. Revolut accepted it as authentic and sent the files.
Revolut will not say which agency’s domain was used, citing the live police investigation. So nobody outside the company knows whether a government mailbox was hijacked, or whether someone already inside it pressed send.
Blockchain investigator ZachXBT, who traces stolen crypto for a living, flagged the leak, highlighting that it reached a small group of users and looked aimed at wealthy ones.
Market Context
What Revolut Says Happened
A Revolut spokesperson told BeInCrypto the bank blocked the sender as soon as it spotted the problem.
Why It Matters
Stolen customer lists have fed phishing risk after breaches. Leaked home addresses have come before violent attacks on holders.
Details
“Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information… Revolut systems and customer funds are unaffected.”
Follow us on X to get the latest news as it happens
The company says it alerted the agency, the police, and its data protection and financial regulators. It has contacted what it calls the limited number of people affected.
The Part the Statement Leaves Out
Revolut says accounts remain secure. That is true, and it is not the problem.
Passcodes, login details, and biometric data were never exposed, the bank told BeInCrypto. No money moved.
The notices sent to customers put it differently. They say the verification selfie went out, and rule out only biometric facial telemetry, meaning the face template a system builds from a photo. The photo itself is another matter.
Those notices list the rest. Passports. Driving licences. Home addresses. Bank statements. A full record of Bitcoin going in and out.
A password takes a minute to change. A passport does not.
There is a second way to read the word sophisticated. By Revolut’s own account, the attacker wrote an email and waited. The clever part happened inside a government mail system. The costly part happened inside Revolut.
The post Revolut Confirms Fake Government Email Pulled Passports and Bitcoin Records: Who Sent It? appeared first on BeInCrypto.