Fintech firm says fraudulent government requests tricked it into releasing customer KYC data, including cryptocurrency holdings Revolut has confirmed that customer data, including passport sc
Fintech firm says fraudulent government requests tricked it into releasing customer KYC data, including cryptocurrency holdings
Revolut has confirmed that customer data, including passport scans and Bitcoin transaction records, was exposed in a recent security incident. The London-based fintech company said the breach stemmed from fraudulent requests that appeared to come from government authorities.
According to reporting on the incident, attackers used fake official channels to request customer verification records from Revolut. The company released know-your-customer, or KYC, information in response, believing the requests were legitimate. That data reportedly included identity documents and records tied to customers' Bitcoin holdings.
Revolut has built its business around rapid account verification and a broad product suite that spans traditional banking and cryptocurrency trading. That scale makes it an attractive target for social engineering attacks aimed at extracting sensitive customer files. KYC obligations require fintech firms to collect and retain passports, proof of address, and transaction histories, creating large repositories of sensitive data that must be protected from both external hackers and impersonation schemes.
The exposure of Bitcoin-related records adds a distinct layer of concern. Unlike traditional bank balances, cryptocurrency holdings tied to identity documents can potentially be traced on public blockchains. That combination could let bad actors link real-world identities to specific wallet activity, a risk that has worried privacy advocates as crypto adoption has grown inside mainstream financial platforms.
Fintech companies operating across multiple jurisdictions routinely receive legal and regulatory requests for customer information. Those requests are supposed to come through verified, secure channels with documented authority. The reported use of fake government requests suggests a gap in how such demands were authenticated before data was released.
Revolut has not detailed the exact number of customers affected or the specific window during which the fraudulent requests were processed, based on current reporting. The company has acknowledged the breach and the role of impersonated official channels in causing it.
The incident arrives as regulators in Europe and beyond continue tightening oversight of how fintech and crypto-adjacent firms handle customer verification data. Data protection rules under frameworks such as the EU's GDPR impose strict requirements on how personal information is collected, stored, and disclosed. A breach involving both passport data and financial records could draw scrutiny from data protection authorities, alongside potential customer inquiries about their exposure.
Revolut has expanded aggressively into cryptocurrency services in recent years, letting customers buy, hold, and trade digital assets alongside conventional banking products. That expansion has increased the volume of sensitive financial and identity data the company stores, a factor that may have contributed to the scale of exposure in this incident.
Market Impact
For the crypto industry, the breach highlights a persistent tension between KYC compliance requirements and the privacy expectations of digital asset users. Firms that combine traditional banking with crypto trading must protect both identity documents and blockchain-linked transaction data, doubling the sensitivity of any single leak.
The incident may prompt other fintech and crypto platforms to review how they authenticate incoming government or law enforcement requests before releasing customer records. Increased scrutiny from regulators could follow, particularly given the involvement of passport data alongside financial and cryptocurrency information.
Revolut's confirmation of the breach underscores the risks fintech firms face when identity verification systems are targeted by impersonation schemes, especially as crypto services deepen the sensitivity of the data involved.
Frequently Asked Questions
What data was exposed in the Revolut breach?
Reporting indicates the breach exposed customer passports and records related to Bitcoin holdings, both collected as part of Revolut's identity verification process.
How did the breach reportedly happen?
According to NFTevening's reporting, fraudulent requests posing as official government inquiries led Revolut to disclose customer KYC data.
Why does exposing Bitcoin records alongside identity documents matter?
Linking passport data to Bitcoin transaction records could allow bad actors to connect real-world identities to blockchain activity, raising privacy and security risks beyond typical financial data leaks.
Has Revolut said how many customers were affected?
Current reporting does not specify the number of customers impacted or the full timeline of the fraudulent requests.
Originally reported by AltcoinGordon, written by Grace Mitchell. Republished with permission.
View the original on AltcoinGordon →
The post Passport and Bitcoin Records Exposed in Revolut Data Breach appeared first on TheCoinrise.com.