Hackers who tricked Revolut into disclosing customer records have moved from private extortion to public leaks, publishing passport copies of named individuals and promising daily releases until the company pays. The breach itself came down to a single email: a request that appeared to come from a government agency, sent from that agency’s own domain, passed authentication checks and was fulfilled. What came back was the complete KYC file on each affected customer, plus something a passport office would never hold, a full record of their bitcoin trading.
Customers affected received identity document copies, verification selfies, residential addresses, IBANs, account statements and full transaction histories, including bitcoin records. Revolut has described the number affected as limited and has not given a figure. It has also not named the agency whose domain was abused, nor the date the request was fulfilled. That silence has become part of the story in its own right.
How a fake request beat real checks
According to a customer notification circulated by on-chain investigator ZachXBT, the request arrived with valid domain authentication credentials. That detail matters. Domain authentication exists precisely to confirm a message genuinely comes from the domain it claims, and it is the mechanism firms lean on when deciding whether a government information request is lawful. A sender operating inside a government agency’s email infrastructure, even without authorization, could pass those checks.
Revolut says it blocked the email address, alerted the agency involved, notified law enforcement and reported the incident to financial regulators. A company spokesperson confirmed to TechCrunch that it was a “sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” Revolut said its systems and customer funds were unaffected. Security researchers have pointed out the gap in that framing: the attackers never needed to break into anything. The company handed the data over itself, and the verification process that was supposed to catch exactly this failed at the one step that mattered.
The customer alert began circulating on September 11, and Revolut confirmed the incident publicly on September 12. Crypto outlets including CoinDesk and crypto.news verified that the transaction histories covered bitcoin specifically. The notification gave no date for the original request and no confirmed count of affected users.
The leak goes public
On September 13 the group behind the theft shifted tactics. The cybersecurity account International Cyber Digest reported on X that passport selfies and identity documents of tennis player Alexander Shevchenko and Felix Römer, chief executive of the crypto casino Gamdom, had been published. In a Telegram message, the hackers said they would keep releasing customer data every day until Revolut “paid up.” That marks the escalation from private extortion, where a company can quietly negotiate, to a public pressure campaign where each day of silence produces new victims.
ZachXBT assessed that the operation targeted high-net-worth crypto users specifically. That combination, real names plus documented crypto holdings plus home addresses, is the profile behind a rise in physical robbery attempts against known holders, the so-called wrench attacks. Fraud, impersonation and targeted phishing are the nearer-term risks for everyone else in the leak set. A leaked IBAN plus a statement plus a selfie is, as SecurityAffairs put it, essentially everything a regulated fintech is required to collect, delivered in one package to the wrong people.
A bad month for KYC data
The incident lands amid a wider stretch of failures at firms holding crypto users’ personal data. Hardware wallet maker Trezor recently saw a support-vendor breach widen to expose tens of thousands more customers. X appeared to suffer a breach of its own that flooded users with password reset emails. Crypto investigator Marc Zeller was among several users who argued the Revolut episode shows know-your-customer rules have concentrated risk on individuals without delivering proportional benefit. The argument writes itself: the data collected to protect customers was the data that endangered them.
Awkward timing for a bank charter
There is also a timing problem for the company. Revolut won conditional approval from the US Office of the Comptroller of the Currency for a national bank charter this month, is reportedly weighing an IPO at a valuation around $200 billion, and launched its euro-pegged EURR stablecoin this year. Its proposed Stamford, Connecticut bank, capitalized at roughly $95 million, would open in 2027 if remaining approvals from the FDIC, the Federal Reserve and the OCC come through. The OCC decision explicitly contemplates the bank letting customers pay remittances with stablecoins and offering Revolut-branded stablecoins through a third party. A disclosure failure that leaked customers’ bitcoin histories to criminals will not help those conversations, and regulators who granted the conditional approval will have read the same headlines as everyone else.
Revolut serves more than 80 million customers worldwide and applied for the charter in March after pivoting away from a plan to acquire a small existing US bank. The company has not said whether it will respond to the extortion demand, and law enforcement involvement suggests it will not. What remains unresolved is the scale. Without a confirmed count of affected users, every Revolut customer who ever traded crypto on the platform has reason to wonder whether their documents will surface in a future daily drop. The company’s own notification, for all its reassurances about blocked addresses and alerted agencies, did not answer the question those customers are actually asking.
