Revolut data breach: The document has been made public, what should I do now?
Changing your password has little effect when your ID copy, verification selfies, and complete Bitcoin transaction history are all held in the same packet by strangers. This is the dilemma for Revolut customers who have received leak notices since September 14, 2026: stolen documents have been released since the early hours of the day. Four points are crucial now.
First, confirm in writing the extent of your own information exposure. Second, cut off paths that allow copies of ID documents to be converted into funds. Third, take the connection between your home address and cryptocurrency holdings seriously. Fourth, exercise your rights with the bank before the deadline.
This article is based on our first assessment. For details on whether you are an affected customer and what role your Bitcoin history played in this incident, please see our September 12 article "Revolut Data Breach: Am I Affected, What Is My Bitcoin History?". This article deals with the subsequent stage: details have been disclosed, changing the premise of the question of "what to do".
Revolut data breach: What to do when files are being made public
Until the weekend, the security incident was still viewed as an outflow of customer data. However, since late September 14, Cointelegraph reported that copies of ID documents and identity verification selfies belonging to Revolut customers had appeared online. According to the media, the attackers announced on Telegram that as long as Revolut did not pay, they would release more datasets every day. An affected customer confirmed to Cointelegraph that the details released matched documents filed by Revolut and that the new bank had written him a letter on Friday.
One point is critical to the assessment: the existence of the ransom request is the attacker's one-sided statement, relayed by an industry publication that quoted the Telegram post. Revolut itself does not confirm any such requirements. There is also a specific bitcoin amount circulated on the aggregation website as a so-called ransom. Since there is no conclusive evidence to prove the authenticity of this figure, this article will not use it as a factual statement.
Despite this, the actual situation is significantly different from last week. As long as the dataset is in the hands of only one criminal group, you need buyers to pose a threat to you. Once it becomes publicly available, this intermediate step disappears and the number of potential scammers grows from a group to anyone who finds the document.
Data fields listed by Revolut in customer emails
Industry publication Bleeding Computer quoted the original notice sent by Revolut to affected customers. According to the text, the incident involved full name, date of birth, occupation, postal address, email address and telephone number. Also included are copies of ID cards or driver's licenses, selfies from identity checks, account statements containing IBAN, withdrawal records and a complete transaction history including Bitcoin transactions.
Revolut stated that the number of users affected was limited, but did not give a specific number. The company said its own systems were not compromised and customer funds were not affected. Both statements are plausible, but do not change your situation much. The damage caused by this incident does not affect your balance, but rather the paper documents.
According to the company, the data outflow was triggered by a forged request that appeared to be an information request from a government authority. Such emergency data requests are an established procedure: in the face of imminent danger, authorities will require user data without waiting for regular judicial channels. The forged request came from a real government domain name and passed a technical sender authentication check. This is where the weakness lies. A technically correct signed email proves the authenticity of the domain name, but it cannot prove whether the request behind it is legal.
Why leaked ID scanning is not within the scope of the German 116 116 hotline
Many of those affected first responded the same way: blocking their ID cards. In Germany, this is done by blocking the toll-free hotline 116 116, but in this case, this is the wrong step. What is blocked there is the online ID function, the eID on the ID card chip. This function requires a physical card plus a six-digit PIN code. A scanned copy cannot trigger it.
Your ID is still in the drawer, and eID is not a way to enter the system. The risk lies with any provider that accepts image documents of ID as proof: credit brokers, mobile operators, mail-order retailers that offer credit purchases, and some loosely vetted trading platforms. Blocking eID will not have any impact there, it will only cost you the right to use digital government services.
Different measures are effective. A criminal report to the police can be filed online through your federal state's digital police station; the case number will later become evidence against claims filed in your name. Apply to major credit bureaus for free copies of your data and check to see if contracts appear that you have never signed. And set up reminders, because identity abuse using copies of identity documents often appears several months later. Germany's Federal Information Security Agency detailed the steps taken by victims of data breaches and online human flesh searches.

The selfie for identity check is not a photo, but a biometric reference value. Because of this, the consequences of losing it are more serious than the leaked email address.

Combining ID scanning with KYC selfies: Problems in vivo testing
Separate ID scanning is a known risk. The combination of a copy of an ID card and a selfie of the same ID check is of another order of magnitude, because the combination is standard proof of opening an account. Many providers require file photos and facial images to be taken, and some even automatically match the two.
The protective measure against this is called "vital detection" and aims to determine whether a real person is sitting in front of the camera or a photo image. Good programs require head movements, changing lighting patterns, or depth capture; weaker programs rely only on uploaded still images. Wherever only still images are needed, leaked verification selfies are immediately available.
This presents a specific task for cryptocurrency users: find which trading platforms hold your ID and close accounts you no longer use. Each dormant registration means one less copy of your document in circulating. Where you remain active, enable two-factor authentication through an authenticator application or security key, rather than via text message, because phone numbers were also part of the leak. Which platforms are regulated in Germany, and how to check this, see our overview of regulated crypto exchanges.
Bitcoin transaction history fell into the hands of others: What can address clustering do
The part of the data package that distinguishes this incident from ordinary bank data breaches is the transaction history. Bitcoin is a public database: every transfer is left on the chain for anyone to check. What blockchain lacks is the link between addresses and people. Account statements containing withdrawal records provide just this link and are free.
"Address clustering" is a technique that derives an entire bundle of addresses from a single known address: When multiple addresses appear together as inputs to a transaction, they are likely to belong to the same wallet. Anyone who knows one of your withdrawal addresses can deduce it from it and often arrive at an estimate of your total position. The technology is neither new nor illegal; analytical companies and investigators have been using it for years. What is new is that the starting point for the derivation is now made public.
The obvious question is whether you should change your address. For future payments, yes; for the past, it cannot be done. Once written into the chain, a transaction cannot be revoked. In practice, this means using a new address for newly received payments, avoiding combining old and new positions in a single transaction, and not depositing and withdrawing large amounts of money through the same platform.
Home address plus cryptocurrency holdings: Putting physical risk under perspective
Online investigator ZachXBT interpreted the incident as a seemingly minor leak that appeared to be deliberately targeted at wealthy users. This is his assessment, not an established fact, but it is noteworthy because it fits the data structure: zip code, date of birth and occupation, coupled with a traceable Bitcoin history, which constitutes a file that transcends the usual purposes of phishing.
We have described this pattern twice in reports, most recently during the Trezor data breach in September, in which the names, phone numbers and home addresses of hardware wallet buyers were exposed. The lessons there also apply here. Don't discuss the amount in the neighborhood or on the phone. Stay suspicious of package notices and calls claiming to be from the banking services team, even if your name, date of birth and recent debit records are correctly quoted. These details are precisely included in the data packet, and callers who know these details cannot prove anything.
Specifically, this also means setting callback rules for yourself at your bank and trading platform. Any process that starts on the phone should not be completed on the phone. Hang up the phone and call the number on the app or account statement. This habit deprives cybercriminals of most of the value they can gain from using your files.
What to do if Revolut's account is hacked
First of all, the important point is to distinguish: in this incident, no accounts were taken over. According to the company, the documents were handed over; login credentials were not stolen. If your account is really controlled by someone else, different procedures apply and start with blocking.
Cards are blocked in the application, or if inaccessible, through bank customer services. Report every unauthorized transaction immediately; under the Payment Services Act, as long as you have no gross negligence, you will usually get a refund for unauthorized payments and the bank must prove authorization. Then change the password for your email inbox because it is the master key for all other logins. Finally, check for connected devices and sessions in all accounts that use the same email address and log out of sessions you don't recognize.
Record each step in writing, including the date and time. Anyone who later claims damages or disputes needs the record.
Next few weeks: Review plan with fixed dates
Identity abuse rarely begins immediately after a security breach. There can be weeks, sometimes months, between the data outflow and the first attack carried out on your behalf, as the data set first needs to be classified, merged, and passed on. As a result, a review plan with fixed dates is more effective than a single crazy afternoon.
This week: sends a 15 access request, submits a criminal report, and switches all two-factor authentication to apps or security keys. Also note which postal addresses and phone numbers are filed with the new bank. Any message that later quotes full of these details will immediately recognize which source the sender used.
Four weeks later: Apply for a copy of your data from a credit bureau and check for entries you don't recognize; every credit inquiry you never make is a warning sign. During the same process, browse the login logs of your most important accounts and report any visits from areas where you are not located.
After three and six months: Repeat the above operations. As long as your passport is circulated as an image document, it will be valuable to scammers until it expires.
In the process, there is one expectation worth giving up. Inspection services that promise to track your data on the black web are actually searching known aggregated databases. Such systems can provide useful clues about old events, but still cannot give you any assurance that everything is going well for new events, because they can only show content that has already been traded in the public domain. Rely on your own message in the 15th response, rather than the green light.
Rights under the GDPR: Article 15 Access, Article 77 Complaint
Notification by Revolut is an obligation under Article 34 of the General Data Protection Regulation (GDPR): Companies must notify affected persons immediately when a disclosure may pose a high risk to them. However, this email only tells you that you have been affected, not how much.
You can obtain the degree, or access, through Article 15 of the GDPR. Request in writing a copy of the data processing about you and a clear statement of what types of data were disclosed to which recipients. The period is one month and can be extended for two months if the company gives reasons. This reply is the only conclusive evidence of what you actually handed over in the case and is free of charge.
If a reply is not received, or a reply is not available, Article 77 of the GDPR applies: Complaint to a supervisory authority, which explicitly includes the supervisory authority in the area where you habitually reside. For German customers, that's the data protection authority of your federal state. Although Revolut Bank UAB is located in Lithuania and the regulatory authorities in the region have jurisdiction under the lead regulatory authority procedures, this has not changed; your state agency accepts complaints and transfers them. The German branch in Berlin is also supervised by BaFin, but BaFin is not responsible for data protection.
Regarding damages under Article 82 GDPR, Germany's position has become clearer since the Federal Court's decision of November 18, 2024 (case No. VI ZR 10/24): mere loss of control over one's own data may constitute compensable non-material damage without the need to prove any abuse. You must explain this loss of control yourself. The amount depends on the case, and the amount awarded is currently at a low level of several hundred euros.
Is Revolut monitored by the Tax Bureau? DAC8 regulations applicable from 2026
This question is asked every time such an incident occurs, and the answer has nothing to do with leaks. No one was monitored. Automatic reporting from January 1, 2026 is something else: Germany's Crypto Asset Tax Transparency Act translates the European DAC8 Directive into domestic law and requires crypto asset service providers to record and transmit tax-related customer and transaction data. The first reporting period is the 2026 calendar year, and data will be sent to the Federal Central Taxation Office before July 31, 2027.
For you, this means two consequences. The details held about you by the encryption provider will increase rather than decrease, and keeping personal records clean is no longer optional. Reported amounts are not your profits either: reported revenues and transactions, and costs are known only to your own documentation. Those who do not keep records will later have to face a figure without any basis. Asset trackers with tax reports solve this problem.
Extortion, ransom, millions of records: What is proven and what is not
There are several narratives surrounding this security incident, and differences are important to your judgment.
It has been confirmed that: The notification of affected persons comes with a list of data fields because Revolut sent it himself and an industry publication repeats it verbatim. It has also been confirmed that ID copies and verification selfies have appeared in public; an affected customer confirmed a match to Cointelegraph.
claims: Extortion. The daily threats came from Telegram posts from the alleged perpetrators. Companies that have been extorted rarely confirm, and Revolut has not done so here. Anyone who mentions a request should explain who made it.
Controversial: A resurfacing incident: During the summer, a database allegedly holding tens of millions of Revolut records was sold on the black market on related forums. German media reported the incident, and Revolut denied its authenticity and pointed out that the material was compiled from other sources. This event must be separated from the current event. Anyone confusing the two will come up with an unconfirmed number of customers affected.
For responding to the next days, this means: Expect very convincing phishing attacks. Whoever knows your name, date of birth, IBAN and recent transactions stops writing clumsy spam. The only reliable test remains the channel, not the content. A real bank will never ask you via email or phone to transfer funds to a secure account, enter a recovery phrase, or install remote access software. If you have any doubts, proceed with the application you installed yourself.
Self-hosting as a consequence: When hardware wallets shorten the data trajectory
The case exposed a feature of custody arrangements that is invisible in daily use: Any provider holding cryptocurrency assets leaves a complete identity file in addition to the balance. This file is the real theme of this incident. A hardware wallet doesn't change everything, but it shortens the trajectory at one decisive point: Balances are no longer held by a third party, and that third party's failure or data breach no longer separates you from your coins.
It's worth being honest anyway. The purchase itself generates data again, as shown in the Trezor leak above; if it can be avoided, never order at your address and only buy from a manufacturer or authorized dealer. Transfers transferred from the exchange to your own wallet are also visible on the chain and can be linked to your account statement. And, the responsibility for restoring the phrase lies entirely with you. Self-custody is a transfer of risk, not an elimination.
For anything that is intended to stay on the platform, the choice boils down to supervision and hosting practices. Ask about the quarantine custody, who the custodian is, and the license for the custodian to operate.
Revolut Data Breach: Summary of Points
- Establish your exposure in writing. Request an access response under Article 15 GDPR today and indicate the date you sent it. Without this list, you will argue over assumptions in the future. At the same time, check which trading platforms hold copies of your ID and close accounts you no longer use; our overview of regulated crypto exchanges shows the importance of retaining ones.
- Separating identity and position. Use a new receiving address, do not merge old and new positions in a single transaction, and transfer what you have held for a long time into your own custody. Our hardware wallet comparison points out the device and its weaknesses.
- Organize the records before the first DAC8 report is issued. Complete acquisition data is your only rebuttal against reported amounts starting from the 2026 reporting period. Tax and asset trackers took over the collection.
(As of September 14, 2026. This article does not constitute investment advice. Price and fee structures are subject to change; please check terms with your provider before purchasing.)

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC