Revolut confirmed it handed over customer passports, home addresses, bank statements and full bitcoin transaction histories to an unknown attacker who posed as a government agency using the agency’s own email domain, in a breach that passed the bank’s own verification checks.
The fintech said the request arrived from an unauthorized email account operating inside a legitimate government agency’s domain infrastructure and carried valid domain authentication credentials, the technical signals meant to prove a message genuinely comes from a government authority. Believing the request was real, Revolut fulfilled it. The company has not said how many customers were affected, which agency was impersonated, or which country the incident occurred in, citing an ongoing police investigation.
Customer notifications circulated online by on-chain investigator ZachXBT describe the leaked package in detail: passports and driving licences, verification selfies, names, dates of birth, occupations, home addresses, email addresses, phone numbers, IBANs, account statements, withdrawal records and complete transaction histories including all bitcoin activity. ZachXBT said the breach appeared limited in size and may have targeted high-net-worth users, which would fit the profile of a targeted operation rather than a bulk data grab.
Everything KYC collects, sent to the wrong people
The incident lands at an awkward moment for the industry’s compliance model. The data handed over is essentially the full set of information a regulated fintech is required to collect for identity verification, delivered in one package to the wrong recipient. For crypto users the exposure is sharper than a typical leak: a password can be changed, but a passport number and home address cannot. Combined with transaction histories that show how much bitcoin a person moves and when, the package is enough for targeted phishing, impersonation or extortion.
Security researchers have warned for months that visible crypto wealth raises physical risk, with a string of so-called wrench attacks against known holders across Europe, including home invasions in France and Spain. ZachXBT flagged exactly that concern in his broadcast about the leak, noting that leaked address data plus transaction histories is the combination that makes such attacks practical.
Revolut’s response emphasizes what was not taken. A spokesperson told Reuters and TechCrunch that systems and customer funds are unaffected, that no passcodes, login details or biometric data were exposed, and that the company blocked the sender as soon as it detected the problem. Revolut says it alerted the impersonated agency, law enforcement, its data protection regulator and financial regulators, and contacted the affected customers directly.
“Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information… Revolut systems and customer funds are unaffected.”
That framing misses the point critics made immediately. The attackers did not need to hack Revolut’s systems to get the data. They used the company’s own lawful disclosure process against it, which is harder to patch than a software vulnerability because the process itself is the product of regulatory obligation.
KYC backlash finds its test case
Criticism mounted fast on X. Marc Zeller, co-founder of the Aave Chan service and a well-known DeFi figure, wrote that he woke up to find his own data exposed, calling it a sharp reminder that KYC rules have produced little meaningful benefit while putting users in harm’s way. He added that Revolut had recently demanded a large volume of personal information from him under threat of account closure within 20 days, and that the leak shows what happens when that data pool is mishandled. The episode gives the crypto industry’s standing argument against KYC a concrete example at one of Europe’s largest fintechs, and the timing is uncomfortable for regulators who have spent two years tightening identity rules.
Revolut serves roughly 80 million customers worldwide and has been building out its crypto products, including a euro-pegged stablecoin launched this year. The company is preparing for a potential public listing with a valuation that reports place as high as $200 billion, and it recently won conditional US approval to become a national bank. A data breach of this kind, involving government-impersonation fraud, is the kind of disclosure regulators reviewing that application will read closely.
The breach also fits a rough stretch for firms holding crypto users’ personal data. Hardware wallet maker Trezor recently saw a support-vendor breach widen to expose tens of thousands more customers, and X appeared to suffer a data breach that flooded users with password resets. Each case shares a pattern: the sensitive data existed because a compliance or support process required it, and the process, not the perimeter, was the weakness.
What changes next
The practical lesson for exchanges and fintechs is that email domain authentication alone is not enough to authorize a law-enforcement style data request. Firms that treat SPF and DKIM passes as verification have effectively outsourced their customer data security to whoever controls an agency mailbox. Out-of-band callback procedures, confirmation through published agency switchboard numbers, staged disclosure and dual sign-off on government requests are the obvious fixes, and several compliance teams posted publicly over the weekend that they were reviewing their own request-handling flows in light of the Revolut case.
For customers, the exposure is permanent. Affected users face a heightened risk of convincing phishing for months, since the attackers hold enough detail to make scams credible, and any of them who hold crypto onchain may want to reassess how traceable their wallets are once identity and transaction data sit in the same hands. Privacy-focused commentators pointed out that this is precisely the scenario zero-knowledge verification proposals were designed to avoid: institutions could confirm a customer is who they claim without retaining a copy of every document.
Revolut has not disclosed a timeline for its investigation, whether affected users will be offered credit monitoring or identity protection services, or whether the data has appeared on any dark-web market. The police investigation into the government domain used in the attack continues, and the company says it will notify regulators of its findings.
