Revolut confirms customer data breach: Identity documents and Bitcoin transaction records were illegally obtained
Revolut has confirmed that a customer data breach occurred. According to reviewed customer notices, after receiving fraudulent information requests sent using legitimate government agency email domain names, identity documents and some customers 'Bitcoin transaction histories were handed over to unauthorized third parties. The incident highlights a long-standing contradiction faced by Bitcoin holders: exchanges and new banks maintain detailed records that directly link personal identities to financial activities on their chains.
Summary of Key Information
Revolut confirmed that identity and contact details, including financial records (reportedly containing Bitcoin activity), had been released to a third party posing as a government requester. Currently, the exact number of customers affected, the institutions being impersonated, the scope of the market involved and the specific date of the fraudulent disclosure have not been disclosed.
Details on Revolut's Bitcoin Data Disclosure Statement
A spokesperson for Revolut told the media that an unauthorized third party obtained sensitive customer information through fraudulent requests from the email domain name of a legitimate government agency. The media reviewed notices sent to affected customers.
The leaked data listed in the notice includes identity and contact details such as birth dates, postal and email addresses, phone numbers, and copies of passports or driver's licenses. Revolut's notice also stated that verification selfies, account statements and transaction history may also be included, but the wording was carefully worded and did not confirm that all fields for each affected customer had been compromised. According to Decrypt, another media outlet, the leaked financial records described the IBAN number, wallet reference number, withdrawal records and complete transaction history, including Bitcoin transactions. This detailed range of Bitcoin data is attributed to the content of the notification in the report rather than the results of independent forensic investigations, and the exact range of data lost to each customer is unclear.
Currently, existing reports have not established the specific number of customers affected, the date of the incident and the jurisdictions involved. Although various parties have consistent descriptions of how Revolut exposed KYC and Bitcoin data in the reports, the specific quantitative issue has not been resolved, and readers should regard the precise scope of influence as undecided.
Questions about alleged forged government requests
The current reported sequence of incidents is "fraudulent requests subsequently leading to data disclosure," which is a timeline description rather than a verified technical explanation that cannot explain how the release was authorized. The legal government mailbox domain name alone does not prove that there is a valid legal requirement. The specific legal basis and request verification process behind this disclosure are still unknown.
Details such as the claimed authoriser, submission channel, request for authentication, and internal release authorization still need to be corroborated. There are currently no independent forensic reports that determine how government domain name email accounts were used or which controls failed, so there is no basis for claiming that domain names were spoofed or servers were compromised.
Revolut said its systems and client funds were not affected, but this was only a company statement and not the result of an independent audit. The company also said that after discovering the scam, it blocked the email address and notified relevant government agencies, law enforcement and regulatory agencies; but did not specify specific authorities and did not establish specific regulatory penalties for the incident.
Revolut told media that the number of customers affected was limited and had contacted them directly, but did not disclose the exact number. When media reports confirmed the matter, they pointed out that online investigator ZachXBT released the content of customer emails on Friday, but the report did not lock in the exact time of the fraudulent disclosure. Similar reports detailing how Revolut disclosed Bitcoin history after false requests also preserved these gaps.
According to unconfirmed reports, the incident specifically targeted high net worth customers, an assessment attributed to ZachXBT and not confirmed by Revolut. There were also unconfirmed reports that the full Bitcoin transaction history and verification selfies of each affected customer were disclosed, but the report used the phrase "may contain" and did not establish an individual scope.
Privacy impact on Revolut Bitcoin users
Linking government-issued identity documents to records of Bitcoin activity is precisely what creates privacy risks and targeted phishing risks, because it ties real-world identities to financial records. These are conditional risks arising from data categories, rather than actual consequences observed in this event.
Existing materials do not confirm the disclosure of login credentials or private keys, account takeover or any loss of Bitcoin. This difference is important: the custody identity record is different from the encryption key that controls the coin, and the reported presence of the wallet reference number in the notification is not evidence that any Bitcoin was transferred. The leak about how Bitcoin wallets were linked to home addresses illustrates concerns about de-anonymization, but does not prove downstream theft.
For anyone concerned about this issue, general precautions still apply. Recommendations from the UK's Information Commissioner's Office (ICO) include checking bank statements and credit files, verifying accidental connections through known official channels rather than links in messages, and considering registering a CIFAS-protected register for additional checks in financial applications. Customers should rely on official communications within the app and contact support services through official channels for any suspicious requests, separating these steps from specific event instructions that Revolut has not yet released.
For Bitcoin holders, this incident reaffirms the basic principle of distinguishing the network's basic layer from its upper custody layer. The security of the underlying protocol, from proof-of-work issuance to self-custody through private keys, is not affected by data leaks from financial institutions; the exposure here is a recording issue, which also reminds people that KYC data retained under the chain is still an ongoing responsibility that cannot be repaired through difficulty adjustments.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC