Bitcoin activity, passports exposed after Revolut falls for fake government request
Revolut, the UK-based fintech and crypto platform, has exposed sensitive user data — including Bitcoin transaction records and passport information — after falling victim to a fraudulent government data request. The incident, reported by CoinDesk, involved bad actors submitting a fake official request that Revolut's compliance team processed without sufficient verification, resulting in the unauthorized disclosure of an undisclosed number of customer records.
The technique used, known as a "fake emergency data request" or EDR fraud, has become an increasingly common attack vector targeting technology and financial firms. Cybercriminals forge law enforcement credentials or compromise official government email systems to submit requests that appear legitimate, prompting companies to hand over user data outside of standard legal channels. High-profile platforms holding financial and identity data have emerged as prime targets due to the sensitivity and market value of the information they store.
For the crypto industry, the breach raises fresh concerns about the security practices of centralized platforms that custody both digital asset activity logs and government-issued identity documents. Regulators in multiple jurisdictions have pushed crypto firms toward stricter Know Your Customer compliance, meaning platforms now hold richer data profiles — increasing the potential damage when breaches occur.
Revolut has not publicly confirmed the full scope of affected users or the jurisdictions involved. Security researchers and regulators are expected to scrutinize the firm's data request verification procedures in the weeks ahead.
Source: CoinDesk