Revolut confirms data breach: Passport and Bitcoin transaction records were reportedly exposed to third parties
Financial technology company Revolut has confirmed a data breach that resulted in customer passports, identification documents and financial records (reportedly including Bitcoin transaction history) being obtained by an illegal third party disguised as a government agency. The company said the leak was caused by receiving a fraudulent request from a legitimate government mailbox domain name. The impact of this incident is spreading rapidly among the most privacy-minded circles in the cryptocurrency space.
Disclosure of details and scope of influence
On September 12, 2026, Revolut confirmed to the media that it had released customer information after receiving emails that appeared to come from real government agencies. This incident did not involve the firewall being breached or the password being cracked, but the attacker induced the operation through very convincing means. Revolut emphasized that its system security and customer funds were not affected. This distinction is crucial: this was a data disclosure incident, not the theft of wallet funds. Given the company's recent aggressive expansion of its presence in the crypto space, including the launch of EURR stablecoins, the exposure of financial records is particularly sensitive.
Specific content of leaked data
The customer notices reviewed listed a range of in-depth identifying information, including dates of birth, postal and email addresses, phone numbers and copies of passports or driver's licenses. The notice also noted that verifying selfies, account statements and transaction history may also be included. However, it should be noted that these categories are marked as "potentially affected" and that this information is not generally exposed for all customers.
Details about Bitcoin come from Decrypt's report. The report stated that the financial records described in the notice included IBAN numbers, wallet reference numbers, withdrawal records and a complete transaction history, including Bitcoin transactions. However, this specific detail has not been independently verified based on the original notice.
It needs to be clear that there is currently no evidence that Bitcoin funds, private keys, passwords or account access rights have been compromised. What is leaked is information, that is, information that allows others to understand your identity and assets, rather than direct control of assets.
How to forge a government request opens a gap
The core charge is based on a single mechanism: the request is forged. Revolut said fraudulent messages came from legitimate government agency email domain names, which made them convincing enough to be enforced. In addition, the situation is described briefly. Revolut does not specify the impersonated authority, jurisdiction, request channel or how its verification process handles the request. These procedural details should not be arbitrarily assumed.
An unproven theory holds that a valid domain name certificate explains why Revolut executed the request. Decrypt described this possibility, but according to unconfirmed reports, email headers, certification results and technical post-mortem analysis reports were never made public. Useful background information is provided here: Email authentication standards such as SPF, DKIM, and DMARC are used to verify that a message really comes from the domain name it claims to be. However, inspection only proves the source of the email and does not indicate whether the sender has the right to request customer records. These are two independent decision-making processes, and confusing the two is the reason why identity fraud is successful.
Issues that have yet to be clarified
Reval told the media that a small number of customers have been affected and have contacted directly, but declined to disclose the exact number of people, the government agencies involved, or whether the leaks were limited to specific markets. The company said it had blocked relevant email addresses and notified relevant government agencies, law enforcement agencies and regulatory agencies, but did not specify the specific targets and has not established any regulatory investigations, enforcement actions or fines.
According to unconfirmed reports, online investigator ZachXBT assessed that the incident targeted high-net-worth users, and this assessment was attributed to him by the media. Since the original investigation post or target evidence was not obtained, it should be regarded as clues rather than established facts.
The potential consequences are obvious: Identity theft and financial privacy risks exist for people whose passports and assets may fall into the wrong hands. These are risks, not observed results. There have been no confirmed fraud, theft of funds or personal injury related to this leak.
Industry response and market response
For cryptographic users, this leak rekindled dissatisfaction with mandatory identity collection. Marc Zeller, founder of the Aave Chan Initiative, said his data had been compromised and used the opportunity to attack KYC (Know Your Customer) data retention practices. He wrote on social media: "I woke up and found my data had been leaked by @Revolut. This is a sharp reminder that KYC has not brought substantial benefits and has put many people at risk."
His view is a sharp opinion, not a forensic conclusion. But this resonates against the backdrop of markets already uneasy about custody and disclosure risks, and a similar theme has been reflected in recent stories such as Blockstream's refusal to pay ransom for the Liquid Bitcoin hack and the SEC's reported shelving of a crypto framework meeting.
Bitcoin itself has almost no fluctuations. The asset was trading at close to US$77,338, down approximately 0.5% on the day, and there was no price reaction directly related to the event. The story is about data, not price.
So the core question hanging over the industry is: If a well-resourced fintech company can be manipulated by social engineering through a seemingly trustworthy email to hand over passports and transaction history, then who is protecting the identity data that KYC rules force everyone to submit?
Disclaimer : This article is for reference only and does not constitute financial or investment advice. There are significant risks in the cryptocurrency and digital asset markets. Be sure to study for yourself before making a decision.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC