Revolut confirms that customers 'KYC and Bitcoin transaction data were leaked due to forged requests.
Financial technology company Revolut revealed to the media that its customers' Know Your Customer (KYC) records and Bitcoin transaction data were exposed to unauthorized third parties after receiving fraudulent requests from legitimate government agency email domain names. The disclosure left the account holder's identity documents and chain history unknown, although the company insisted its systems and customer funds had not been affected.
This incident was not a network intrusion in the traditional sense, and there was no on-chain transfer of Bitcoin. Instead, it was a data disclosure glitch on one of Europe's largest fintech platforms and had a specific Bitcoin dimension: the leaked material reportedly included wallet reference numbers and transaction history. Such information could weaken the anonymity that underpins the Bitcoin privacy model, potentially affecting individual holders.
Summary of key information
- Revolut stated that customers 'KYC information and Bitcoin transaction data have been leaked to unauthorized third parties.
- According to reports, the leak originated from a false request disguised as a government agency's mailbox.
- Revolut confirmed that it disclosed sensitive customer information to unauthorized third parties after receiving a fraudulent request through a legitimate government agency email domain name.
Detailed situation and impact analysis
Revolut confirmed to TechCrunch that the company disclosed sensitive customer information to unauthorized third parties after receiving fraudulent requests through legitimate government agency email domain names. "Know your customer"(KYC) refers to the user identification records that financial institutions must collect and maintain in accordance with the law.
TechCrunch reviewed notices sent to affected customers, which listed identification and contact details, including dates of birth, postal addresses, email addresses, phone numbers, and copies of identification documents such as passports and driver's licenses. The notice states that the data disclosed may also include verification selfies, account statements and transaction history, but it should not be assumed that all affected customers contain these types of information.
Customer notices reported by crypto.news show that account statements that may be disclosed include Bitcoin wallet reference numbers, while transaction histories include Bitcoin transaction records. The original notice was not independently verified, and crypto.news reported that the notice was originally shared by online investigator ZachXBT.
A spokesman for Revolut said that only a few customers were affected and had been directly contacted, but did not disclose the exact number, the markets affected or the government agencies involved. Revolut also said its systems and client funds were not affected. Although this guarantee explains the security of fund custody and infrastructure, it does not establish the conclusion that the personal information disclosed will not be subsequently misused. This echoed earlier reports of how KYC data and Bitcoin history were leaked, emphasizing that the risks here lie at the information level, not the custody level.
False request details
The leak followed what Revolut described as a fraudulent request from a legitimate government agency's mailbox domain name. According to crypto.news, Revolut described the request as carrying valid domain authentication credentials, but the notice did not explain how the sender gained access to the agency's domain name.
The background information provided bydoes not specify the domain name, organization, country, request channel or the verification process Revolut applies before responding. Messages originating from government domain names do not in themselves establish government involvement, and existing reports do not show who controlled the address or how successful the request was. Similar uncertainty surrounds reports of how Bitcoin activity was leaked in forged requests.
Revolut said it had blocked the email address and notified relevant government agencies, law enforcement and regulatory agencies. These are company statements rather than independently confirmed results of regulatory investigations, and reports on how passports and Bitcoin history were disclosed after the request do not verify technical access methods.
Details of the Revolut data breach that have yet to be clarified
Several important details are missing from current reports. The number of customers affected, the jurisdictions affected, the identities of government agencies, the dates of the fraudulent requests and the dates Revolut became aware of the problem are unknown, and it is unclear whether each type of data listed applies to each notifying user.
This distinction is crucial under UK data protection rules. The Office of the Information Commissioner in the UK defines personal data disclosure as unauthorized disclosure or sending of personal data to the wrong recipient, so network damage is not a necessary condition for the characterization of the incident. Its guidelines state that notifiable UK GDPR leaks must be reported without undue delay, where feasible, and completed within 72 hours of becoming aware; and Article 33(5) requires the recording of all leaks, their impact and remedial measures, whether or not notification to regulatory agencies is required.
This documentation standard is a noteworthy reporting gap. Blocking the request address and stating that funds were not affected does not in itself complete the accountability record described in the guidelines; the source does not identify the applicable jurisdiction, the date of notification, or any specific regulatory agency investigation. Details that Revolut may share privately with clients or regulators are separate from what is currently confirmed in public reports. Early accounts about passports and Bitcoin data reportedly obtained by attackers also left these questions unanswered.
Long-term concerns about Bitcoin holders
For Bitcoin holders, the continuing concern is correlation. Wallet reference numbers and transaction history tied to verified identities can be used to cluster and unanonymize addresses, a result that cannot be reversed by any difficulty adjustment or hash rate value. At the time of the study, the transaction price of Bitcoin was approximately US$77,168, which did not change much that day. There was no evidence that the leak was related to price fluctuations; the monetary attributes of the network remained intact, but the privacy leak occurred completely offline, and the immutable nature of the ledger could not do anything about it.
Disclaimer : This article is for reference only and does not constitute financial or investment advice. There are significant risks in the cryptocurrency and digital asset markets. Be sure to conduct independent research before making a decision.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC