Revolut Leaks Passports and Bitcoin Histories in Data Breach

9/14/2026
3min read
Denislav Manolov's Image
by Denislav Manolov
Crypto Expert at Airdrops.com
9/14/2026
3min read
Denislav Manolov's Image
by Denislav Manolov
Crypto Expert

Revolut disclosed sensitive customer information to an unauthorized third party after receiving a fraudulent data request that appeared to originate from a legitimate government agency.

According to a customer notification shared by crypto investigator ZachXBT, the request came from an unauthorized email account operating through the government agency's official domain. Because the message carried valid domain authentication credentials, Revolut believed the request was legitimate and provided the requested information.

A Revolut spokesperson later confirmed the incident to TechCrunch, describing it as a “sophisticated external impersonation scam” in which an unauthorized party used a legitimate government agency domain to submit fraudulent information requests.

The company said only a “limitednumber of customers were affected, although it has not disclosed the exact number or identified the government agency involved.

Passports and Bitcoin Transactions Exposed

The information disclosed was extensive, covering personal identification, contact details, verification documents and financial activity.

According to the customer notice, exposed information could include a person's full name, date of birth, occupation, postal address, email address and telephone number.

More sensitive verification data was also affected, including copies of passports or driver's licenses and selfies submitted during identity verification. Revolut said biometric facial telemetry data was not exposed.

For cryptocurrency users, the compromised financial information was particularly significant. The disclosure reportedly included account statements, IBAN details, wallet reference numbers, withdrawal records and complete transaction histories, including Bitcoin transactions.

Revolut stressed that its internal systems were not compromised and customer funds were not affected.

Revolut Alerts Authorities

After identifying the fraudulent request, Revolut said it blocked the email address involved and contacted the impersonated agency, along with law enforcement authorities and relevant regulators.

“A sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”

The incident differs from a traditional cyberattack because attackers did not need to breach Revolut's infrastructure directly. Instead, they allegedly exploited the credibility of an authenticated government email domain to convince the company to voluntarily disclose customer information.

Revolut has not explained exactly how the attacker obtained access to the government domain or what additional safeguards are being introduced for future information requests.

Crypto Holders Face Additional Security Risks

ZachXBT suggested that the incident may have specifically targeted high-net-worth individuals, although that claim has not been independently confirmed.

Such concerns have become increasingly serious because of the rise in physical attacks against cryptocurrency holders. So-called “wrench attacks” involve criminals using threats, kidnapping or physical violence to force victims to transfer digital assets or reveal wallet credentials.

Information combining a person's identity, physical address and detailed cryptocurrency transaction history could therefore create risks extending beyond conventional financial fraud.

The incident also triggered renewed criticism of know-your-customer requirements, with some crypto users arguing that centralized databases containing identity documents and financial histories can become valuable targets for criminals.

Crypto Companies Face Growing Data Threats

Revolut's disclosure comes amid a broader series of security incidents involving companies holding sensitive cryptocurrency customer information.

Hardware wallet manufacturer Trezor recently warned users about phishing emails following a breach involving a third-party provider, while other incidents have demonstrated how stolen personal information can be used to create increasingly convincing attacks against crypto holders.

The Revolut incident highlights a different vulnerability: even when a company's own infrastructure remains secure, fraudulent government or law-enforcement requests can potentially become another route to sensitive customer data.

The disclosure also arrives during an important period for Revolut. The fintech company launched its EURR euro-backed stablecoin earlier in 2026 as part of a broader push into digital assets and is reportedly considering a future initial public offering.

For affected customers, however, the immediate concern is that highly sensitive information-including identity documents and complete Bitcoin transaction histories-was provided to an unauthorized party despite Revolut's systems themselves remaining uncompromised.

Share with your friends on social media:

Join the community and don't miss a crypto giveaway.

Subscribe for updates by e-mail with the latest research reviews, airdrop news, reward programs, event updates about upcoming airdrops.

By entering your email address you are accepting our Terms & Conditions and Privacy & Cookie Policy.