Revolut customers began receiving unusual breach notifications this week after the digital bank confirmed that a subset of user records — including passport scans, verification selfies, and Bitcoin transaction histories — were handed over to an unauthorized party posing as a government agency. On-chain investigator ZachXBT surfaced the customer notice, describing an incident distinct from a typical hack: no systems were breached, no passwords stolen, and no funds moved. Instead, Revolut simply handed the data over voluntarily, believing the request was legitimate.
According to the notice, an attacker gained access to an actual official government agency's email domain — not a convincing lookalike, but the real thing — and used it to submit a data request that passed Revolut's authentication checks. In its own words, Revolut said the communication “carried valid domain authentication credentials,” and was therefore “fulfilled under the reasonable belief that it was an authentic government agency request.” The company has confirmed there was no intrusion into its own systems and no unauthorized account access or withdrawals.
The scope of what was disclosed is unusually broad for a crypto-adjacent breach. Affected customers' files reportedly included full names, dates of birth, occupations, home addresses, phone numbers and emails, copies of passports or driver's licenses, KYC verification selfies, account statements with IBANs, complete transaction histories — including Bitcoin transactions and wallet reference numbers — and withdrawal records. Notably absent from the exposure were wallet private keys, account passwords, and full card numbers, meaning direct theft of funds through the leaked data alone looks unlikely.
Related: ZachXBT's New Fraud Site Will Reject Cases From 7 Countries
How many users were affected remains unclear. Revolut's notice does not confirm a total count, though the person who surfaced it described the incident as appearing limited in scope and potentially concentrated among high-net-worth account holders — the kind of customers whose Bitcoin holdings and financial statements would carry the most value to a targeted attacker. That combination of specificity and ambiguity has fueled speculation that the fraudulent request may have been built to extract records on a narrow set of individuals rather than cast a wide net.
The mechanics of the attack echo a broader pattern in which platforms get compromised through social engineering rather than through system intrusion. Fake law-enforcement or agency requests have increasingly become a preferred route that bypasses hardened technical defenses entirely: rather than breaking into a database, an attacker only needs to convince a compliance or customer-support team that a request is genuine. Financial platforms holding crypto-linked accounts are considered especially attractive targets precisely because their KYC files double as a map of a customer's on-chain wealth — a risk regulators have flagged before, including in a recent DOJ investigation into a mass password attack on X that specifically targeted crypto-linked accounts.
The incident lands at an awkward moment for a company positioning itself as a serious player in both traditional finance and crypto. Under UK data protection rules, companies are generally required to report material breaches to the Information Commissioner's Office within 72 hours and to assess the risk of identity theft or financial harm to affected individuals. Whether Revolut met that window, and what remediation it is offering exposed customers, has not been detailed publicly. The episode also lands against a backdrop of intensifying scrutiny of how crypto-linked financial data is handled and protected, with Tether recently touting over $5 billion in frozen illicit assets as evidence that on-chain enforcement tools are maturing even as breaches like this one show how much can still go wrong on the identity-verification side of the industry.
For crypto users generally, the episode is a reminder that KYC-linked personal and transaction data held by centralized platforms remains a standing target — one that doesn't require a technical exploit to compromise, just a convincing-enough piece of paperwork. As crypto.news reported, the breach underscores how identity-verification pipelines built to satisfy regulators can become a single point of failure when the “regulator” asking for data turns out to be someone else entirely.
FAQ
What personal data was exposed in the Revolut breach?
Names, dates of birth, occupations, home addresses, phone numbers, emails, passport or driver's license copies, KYC selfies, account statements with IBANs, and full transaction histories including Bitcoin activity and wallet reference numbers.
Were funds, private keys, or passwords stolen?
No. Revolut says there was no system intrusion, no unauthorized account access, and no withdrawals; wallet private keys, passwords, and full card numbers were not part of what was disclosed.
How did the attacker get Revolut to hand over the data?
They used an actual official government agency's email domain, which carried valid authentication credentials, leading Revolut to fulfill the request believing it was a genuine government inquiry.
How many customers were affected?
Revolut has not confirmed a total count; the incident is reported to appear limited in scope, possibly concentrated among high-net-worth account holders.
