Passports, selfies, and residential details were also exposed after the digital bank accepted a fraudulent request as genuine, though no customer money was taken.
A fake government email bypassed security measures at digital banking giant Revolut this week, exposing the residential addresses, identity documents, and Bitcoin transaction records of a broad group of customers.
The request seemed to originate from a genuine government agency and included credentials that passed Revolut’s verification checks. Customer information was handed over before the company contacted the agency separately and confirmed that the request was fraudulent, according to notices sent to affected users.
The files reportedly contained passports or driving licences, verification selfies, names, birth dates, occupations, residential addresses, email addresses, phone numbers, IBANs, account statements, withdrawal records, and complete transaction histories, including all Bitcoin activity.
In its email, the company said customer funds remained secure and confirmed that affected users and regulators had since been notified, while the source of the request was blocked.
The main weakness was found in the authorization process. After the request passed Revolut’s internal checks, an individual posing as a government official gained access to the same highly sensitive information the bank had gathered for identity verification and compliance purposes.
Such security breaches are becoming more difficult to prevent as the internet grows increasingly driven by AI.
Persuasive emails, documents, fake identities, and official-looking requests are becoming cheaper to create at scale, while financial firms continue collecting increasingly detailed records about their customers, their locations, and how they transfer money.
The breach highlights a more immediate role for privacy tools such as zero-knowledge proofs. ZK systems can let users demonstrate that an identity check has been completed or that they meet a specific requirement without exposing much of the passport, address, or other underlying data used for verification.
Bitcoin makes this divide particularly evident. Its blockchain publicly records transactions, while personal information such as passports, residential addresses, and occupations remains outside the network. Financial intermediaries can link these separate data points, effectively turning customer records into a profile that connects a real individual with their onchain activity — information that malicious actors could exploit when targeting major bitcoin holders.
Onchain investigator ZachXBT, who highlighted the incident, said in a Telegram post that the breach appeared relatively small in scope and could have been aimed at users with substantial wealth.
As AI-driven impersonation becomes easier, the security debate is shifting from how effectively institutions safeguard customer data to questioning how much sensitive information they truly need to collect, store, and disclose in the first place.
