Fintech company Revolut is suspected of having leaked personal identifiable information (PII) of some users after being tricked by a forged government agency's request for information submission. According to on-chain detective ZachXBT, hackers impersonated the official email domain of a real government agency to request customer information. Revolut trusted the email authentication information and provided the data. The leaked data reportedly includes names, addresses, copies of identification cards, as well as Bitcoin transaction history and account details. However, facial biometric data was excluded from the leak. ZachXBT analyzed that the damage primarily targeted high-net-worth cryptocurrency holders. Revolut has sent relevant security alerts to affected users and advised them to reconfirm suspicious inquiries through the official in-app channels.