Revolut mistakenly released sensitive identity documents and Bitcoin transaction histories for high-net-worth clients after processing a fake government data request that bypassed standard email authentication controls.
Revolut failed to stop an attack that exposed passports, driver's licenses, and detailed Bitcoin transaction records belonging to some of its wealthiest customers. The breach happened when the company responded to a fake data request sent from a real government agency email address. As a result, sensitive customer information was sent to an outside party without authorization.
The breach exposed not only identity documents but also Bitcoin withdrawal records and transaction histories, linking real-world identities to on-chain activity.
Customers affected by the breach were told that the leaked data could include copies of passports or driver's licenses, names, dates of birth, addresses, phone numbers, email addresses, IBANs, and account statements. For those with Bitcoin activity, the exposure also covered withdrawal records and full transaction histories. Biometric facial data was not included, as confirmed in notifications to users and in media reports.
Revolut's public statements, cited by Reuters, repeat that "Revolut systems and customer funds are unaffected." The company has not said how many people were impacted. The incident has renewed concerns about the risks of centralized data collection by fintech companies and exchanges, especially as regulations require them to gather large amounts of personal and financial information for KYC and AML compliance.
Centralized platforms like Revolut are required by law to collect and store extensive KYC and AML data, which can become a single point of failure if compromised. This incident underscores the ongoing tension between regulatory compliance and user privacy in the crypto sector.
Revolut described the breach as a "sophisticated external impersonation attack" and said it blocked the sender and notified authorities as soon as it was detected. As of September 12, 2026, there has been no public press release with a specific incident number, and there is no evidence of stolen funds or direct financial losses. The main concern is the exposure of identification and financial documents, not unauthorized withdrawals from accounts.
The breach is especially troubling for Bitcoin holders. Linking verified identities to blockchain addresses can let attackers trace a user's entire transaction history, removing the pseudonymity that many in the crypto community expect. This risk is greater for high-net-worth individuals, whose financial activity is more likely to attract attackers. Blockchain analytics firms report that Bitcoin's daily on-chain transaction volume often exceeds $10 billion, with large transfers usually tied to institutional or wealthy users.
The Revolut incident shows that even regulated fintech companies with advanced compliance systems can fall victim to targeted social engineering and infrastructure attacks. As previous cases have shown, the overlap between traditional finance and crypto creates new ways for privacy breaches and financial exploitation. Users whose data was exposed should be alert for follow-up attacks, including phishing and identity theft.