By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Revolut Leaks User Data Via Fake Government Request

Fintech company Revolut disclosed sensitive user data, including passport scans and detailed Bitcoin transaction histories, in response to a fraudulent request that originated from an email address mimicking a government agency's domain. The breach, which affected a "limited" number of users, highlights a critical vulnerability in the company's data handling protocols. The fraudulent request was reportedly sent from an email address that appeared to belong to a legitimate government entity, leading Revolut's systems to process it as a valid directive. This incident underscores the sophisticated tactics employed by malicious actors to exploit corporate security measures. The compromised information included personally identifiable documents and a comprehensive record of cryptocurrency trading activities, specifically for Bitcoin transactions. The exact number of affected users has not been publicly disclosed, but the term "limited" suggests it was not a widespread, mass data leak. However, the nature of the data exposed—identity documents and financial transaction histories—poses significant risks of identity theft and financial fraud for the individuals involved. Revolut has stated that it is investigating the incident thoroughly and has implemented additional security measures to prevent similar occurrences in the future. The company is also reportedly in the process of notifying the affected users and offering support to mitigate potential harm. This event brings renewed attention to the challenges faced by financial technology companies in safeguarding customer data against increasingly advanced cyber threats. Regulatory bodies are likely to scrutinize Revolut's security practices and compliance with data protection laws following this incident. The incident also raises questions about the verification processes employed by financial institutions when responding to requests for user data, particularly those that appear to originate from official channels. The ability of a fraudulent email to bypass security checks suggests a need for more robust authentication and validation procedures. The exposure of Bitcoin transaction histories is particularly concerning, as this data can reveal patterns of activity, holdings, and potentially link users to specific wallets and exchanges, thereby compromising their financial privacy and security in the digital asset space. The company's response, including user notification and enhanced security, will be crucial in rebuilding trust and demonstrating its commitment to data protection. The long-term implications for Revolut's reputation and regulatory standing remain to be seen as the investigation unfolds and further details emerge regarding the scope of the breach and the specific vulnerabilities exploited.
Original source — read the full reporting at the publisher:
Read on DecryptGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.