A fraudster obtains access to some Revolut customers’ personal and financial information by sending a request that appears to come from a government agency, according to multiple reports. The exposed material includes identity documents such as passports and selfies, along with full cryptocurrency transaction histories for a limited number of users.

Both outlets describe how the request uses a government agency email domain to appear legitimate. Decrypt reports that Revolut fulfills the request and that the information exposure involves ID documents and complete crypto transaction histories. Cointelegraph similarly states that customer data is revealed using a fake government email and emphasizes the same categories of data, including passports, selfies, and transaction histories.

While the accounts align on the broad outline—fraudulent government-branded email, limited number of affected users, and exposure of identity and crypto records—details like the specific agency, number of users, and timeline are not provided in the excerpts. The reports frame the incident as a case of credentialed-looking fraud leading to customer-data disclosure rather than a hack described in the source summaries.