• 4 mins read
  • Published

Revolut Data Breach Exposes Wealthy User Passports and Bitcoin Activity

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Revolut Data Breach Exposes Wealthy User Passports and Bitcoin Activity EgonCoin © egoncoin.com
Revolut Data Breach Exposes Wealthy User Passports and Bitcoin Activity © egoncoin.com

Revolut mistakenly released sensitive identity documents and Bitcoin transaction histories for high-net-worth clients after processing a fake government data request that bypassed standard email authentication controls.

Revolut failed to stop an attack that exposed passports, driver's licenses, and detailed Bitcoin transaction records belonging to some of its wealthiest customers. The breach happened when the company responded to a fake data request sent from a real government agency email address. As a result, sensitive customer information was sent to an outside party without authorization.

After discovering the breach, Revolut blocked the sender and alerted the government agency, law enforcement, and relevant regulators. The company said its internal systems and customer funds were not affected. According to Revolut, the incident was caused by an external impersonation attack, not a direct hack of its infrastructure.

The breach exposed not only identity documents but also Bitcoin withdrawal records and transaction histories, linking real-world identities to on-chain activity.

EgonCoin Analyst

Customers affected by the breach were told that the leaked data could include copies of passports or driver's licenses, names, dates of birth, addresses, phone numbers, email addresses, IBANs, and account statements. For those with Bitcoin activity, the exposure also covered withdrawal records and full transaction histories. Biometric facial data was not included, as confirmed in notifications to users and in media reports.

Revolut's public statements, cited by Reuters, repeat that "Revolut systems and customer funds are unaffected." The company has not said how many people were impacted. The incident has renewed concerns about the risks of centralized data collection by fintech companies and exchanges, especially as regulations require them to gather large amounts of personal and financial information for KYC and AML compliance.

Reuters reported that the attacker took advantage of trust in official government emails by using a real agency domain. This let the fake request slip past standard email authentication checks like SPF, DKIM, and DMARC, and bypassed typical anti-phishing defenses. The case highlights a weak spot for financial firms that rely on email to verify regulatory requests.

Centralized platforms like Revolut are required by law to collect and store extensive KYC and AML data, which can become a single point of failure if compromised. This incident underscores the ongoing tension between regulatory compliance and user privacy in the crypto sector.

Revolut described the breach as a "sophisticated external impersonation attack" and said it blocked the sender and notified authorities as soon as it was detected. As of September 12, 2026, there has been no public press release with a specific incident number, and there is no evidence of stolen funds or direct financial losses. The main concern is the exposure of identification and financial documents, not unauthorized withdrawals from accounts.

The breach is especially troubling for Bitcoin holders. Linking verified identities to blockchain addresses can let attackers trace a user's entire transaction history, removing the pseudonymity that many in the crypto community expect. This risk is greater for high-net-worth individuals, whose financial activity is more likely to attract attackers. Blockchain analytics firms report that Bitcoin's daily on-chain transaction volume often exceeds $10 billion, with large transfers usually tied to institutional or wealthy users.

The Revolut incident shows that even regulated fintech companies with advanced compliance systems can fall victim to targeted social engineering and infrastructure attacks. As previous cases have shown, the overlap between traditional finance and crypto creates new ways for privacy breaches and financial exploitation. Users whose data was exposed should be alert for follow-up attacks, including phishing and identity theft.

Related articles