
Revolut Discloses 680 Customers' Passports and Crypto Records in Social Engineering Attack
Revolut confirmed Friday that scammers impersonating government officials obtained personal and financial data on 680 customers through a fraudulent request. Disclosed information included passports, verification photos, addresses, IBANs, and complete Bitcoin transaction histories.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
How the Attack Unfolded
Revolut confirmed that scammers used a spoofed government email account to trick the company into releasing customer data. The attackers posed as legitimate authorities, and Revolut treated the request as authentic and complied without proper verification. According to the fintech's notification to affected customers, the disclosed information included passport or driver's license copies, verification selfies, names, dates of birth, occupations, home addresses, phone numbers, IBANs, account statements, and complete transaction histories including Bitcoin withdrawal records.
Scope and Affected Data
Revolut notified 680 customers of the breach on Friday. The company has not yet disclosed how it verified which customer records were accessed or whether the attacker successfully exploited the data for fraud or further social engineering. Crypto.news reported the UK Financial Conduct Authority has launched a formal probe into the incident.
Regulatory and Security Implications
The incident highlights a significant gap in Revolut's verification procedures for third-party requests. A fintech handling both fiat and cryptocurrency accounts faces heightened responsibility for vetting government inquiries, particularly when the request targets sensitive identity and transaction data. Revolut did not immediately respond to requests for further detail on whether it has implemented additional verification layers for official requests.
Why It Matters
For Traders
If your Revolut account holds crypto, verify that your withdrawal history and account details were not in the 680-customer subset; account takeover risk is elevated if personal data was compromised.
For Investors
Regulatory action by the FCA could lead to fines, mandatory security upgrades, or restrictions on Revolut's crypto services, affecting user retention and profitability.
For Builders
This breach underscores the importance of airgapped verification for custody platforms and the risk of social engineering at the company-level; protocols integrating with CEXes should model worst-case disclosure scenarios.
This article is for information only and is not financial advice. Read the full disclaimer.






