Revolut handed a fraudster copies of customers’ passports, their verification selfies, their home addresses and their complete Bitcoin transaction histories, after a data request arrived from a real government agency email domain and passed every check the bank makes.
Affected customers were notified on Friday 11 September. Revolut has not said how many people were involved, describing it only as a limited number.
Nobody Hacked Revolut
This was not a breach in the way the word is normally used. No database was compromised, no malware was involved, no password was stolen and no customer account was accessed.
What failed was the channel banks use to answer lawful requests from police, prosecutors and regulators. An unauthorised account operating inside a genuine government agency’s email domain submitted a request for customer information. Because the domain was authentic, the message passed authentication, and Revolut treated it as legitimate and sent the files.
Only afterwards, on contacting the agency through separate channels, did the bank establish that nobody there had sent it.
‘Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,’ a company spokesperson said.
Revolut blocked the address, alerted the agency to the unauthorised account operating within its domain, and notified enforcement agencies and financial regulators. It said its systems and customer funds were unaffected.
What Actually Left the Building
The notification sent to affected customers sets out a far longer list than a typical breach disclosure.
It covers full names, dates of birth and occupations. Home addresses, email addresses and phone numbers. Copies of identity documents, meaning passports or driving licences, along with the verification selfies customers upload when they open an account.
Then the banking side: IBANs, account status and opening dates, account statements, withdrawal records and complete transaction histories, including every Bitcoin movement and the wallet references attached to them.
Why That Combination Matters More Than the Usual Leak
Most data leaks give an attacker fragments. This one gives a complete profile of a specific person, and the crypto element makes it materially worse.
Someone now holds, for a set of named individuals, a verified identity document, a photograph of the person’s face, a residential address, and a full record of how much Bitcoin they hold and where it moves. Blockchain investigator ZachXBT has said the incident appears limited in size and aimed at high-net-worth users, which is the profile that makes those four things dangerous together.
That is precisely the information a physical attack requires. Research published by Chainalysis in August documented 46 violent attacks on crypto holders in the first half of 2026 with losses above $30 million, and found home invasions had risen to 37% of recorded cases from 26% in 2023. The report noted attackers increasingly target relatives and acquaintances rather than the holders themselves.
Nothing links this disclosure to any such attack, and there is no suggestion the data has been used. But a leak that pairs a home address with a verified Bitcoin balance is a different category of exposure from a leaked email list.
The Argument the Industry Keeps Having
The incident reopened a familiar dispute about identity verification. Aave contributor Marc Zeller wrote that he had woken up to find his data leaked by Revolut, adding that it was a ‘sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way.’
The point has force here because the usual defence of mandatory identity collection is that regulated institutions keep the data safe. In this case the data was not stolen. It was handed over, through a process designed to be trusted, to someone who asked for it convincingly.
What Affected Customers Can Do
Revolut says it has contacted those involved directly. Anyone who received that notification should assume their identity documents and their transaction history are in criminal hands, and treat any unexpected contact referencing their Revolut account, their holdings or a government matter as hostile.
The identity documents cannot be recalled. A passport copy and a matching selfie remain useful to an attacker indefinitely, which is the part of this that does not expire.


