Bitcoin Transaction Histories Exposed in Revolut Data Incident
Covered by 2 sources · 2 articles
Revolut inadvertently disclosed customer identification documents and complete Bitcoin transaction records after processing what appeared to be an official information request from a government agency. The request originated from the agency's legitimate email domain and passed authentication checks, but was later determined to be fraudulent. The exposure affected a limited number of users whose data was compromised through the company's fulfillment of the unauthorized demand.
The incident highlights a vulnerability in how fintech platforms verify law enforcement and regulatory requests - authentication of the sender's email domain alone proved insufficient to catch the fraudulent request before sensitive customer information was released.
- Revolut released crypto transaction histories and KYC data based on a falsified government information request that passed email verification.
- The request used a legitimate government email domain, suggesting the fraud involved domain spoofing or account compromise rather than obvious impersonation.
- The exposure was limited in scope, though Revolut has not specified how many accounts were affected.
All coverage
Revolut Leaks Passports, Bitcoin Transaction Histories to Fake Government Request
The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.
Bitcoin Transaction Histories Exposed in Revolut Data Incident
Revolut disclosed customer KYC and Bitcoin records after a fraudulent government request passed email authentication checks.