Revolut handed over passports, home addresses and full bitcoin transaction histories to a fraudster who sent a fake government information request that passed the bank’s own security checks. The London-based digital bank confirmed the breach on Saturday. No customer funds were lost and no accounts were hacked.
According to notices sent to affected users and reports from CoinDesk and Hackread, the request appeared to come from a legitimate government agency and carried credentials that cleared Revolut’s verification process. Staff released the data before anyone separately contacted the agency and discovered the request was forged. Revolut has not named the agency whose domain was used, citing an ongoing police investigation.
What exactly left the building
The files included passports or driving licences, verification selfies, names, dates of birth, occupations, home addresses, email addresses, phone numbers, IBANs, account statements, withdrawal records and complete transaction histories, including all bitcoin activity. Revolut says passwords, login details, biometric data and customer funds were not exposed.
The company has not said how many customers were affected, how many fraudulent requests it processed, or when the data was handed over. Reports suggest the attack may have targeted high-net-worth customers, which would make the bitcoin records the most valuable part of the haul. On-chain observers including ZachXBT commented on the breach within hours of the first reports.
Not a hack, something harder to defend against
This was not a breach of Revolut’s systems in the conventional sense. The bank itself released the information after accepting a fraudulent request as genuine. That distinction matters for liability and for how the incident gets regulated, but it offers cold comfort to the customers whose documents are now in criminal hands.
Revolut described the event as a “sophisticated external impersonation attack” involving an unauthorized third party using a legitimate government agency email domain. After discovering the fraud, the company blocked the sender address, alerted the agency, notified police and financial and data protection regulators, and informed affected customers.
Why bitcoin records raise the stakes
For crypto users the exposure is worse than an ordinary banking leak. A password can be changed, but a passport number and home address cannot. Combined with a full record of bitcoin transactions, the data supports highly targeted phishing, extortion and physical threats. Holders of large amounts become identifiable by address and pattern of activity, something on-chain analysts have long warned about.
The incident also strengthens the case for privacy-preserving verification, where institutions confirm a customer’s identity while retaining less raw data. The less a bank stores, the less a single forged letter can pull out the door. Zero-knowledge identity tools exist, but adoption among regulated banks remains thin because compliance teams prefer holding full documents they can produce to auditors on demand.
AI-assisted fraud raises the bar
CoinDesk’s reporting framed the episode as an example of how AI-assisted impersonation can exploit authorization systems. Forged documents and convincing institutional correspondence have become cheap to produce, and the weakest link is the human process that decides what to release. Revolut’s checks were passed by an email, not by a stolen credential.
Banks across Europe face the same exposure. Government information requests are routine, they arrive by email, and each one is a decision point where a single mistake leaks everything on file. The UK’s Information Commissioner’s Office is among the regulators notified, and enforcement questions will turn on whether Revolut’s verification procedures were reasonable for the sensitivity of the data involved.
Revolut has a mixed record on fraud controls. The Financial Times reported in 2022 that the company’s payments operations had drawn scrutiny over fraud losses, and the bank later obtained a UK banking licence with restrictions. Its customer base has since grown past 50 million accounts globally, which multiplies both the value of its data warehouse and the number of staff handling sensitive requests.
The regulatory picture
Under the UK GDPR and its EU equivalent, a data controller must notify the supervisory authority within 72 hours of becoming aware of a personal data breach, and must describe what happened, how many people are affected and what the consequences are. Revolut’s disclosure so far stops short of all three specifics, which regulators are likely to press it on. If the investigation finds the verification process was inadequate for data of this sensitivity, the ICO can levy fines calculated as a percentage of global turnover.
There is also the question of notification timing. Customers received notices after the company discovered the fraud, but the gap between the release of data and the discovery remains undisclosed. In impersonation cases that gap can stretch for weeks, and every day of delay extends the window in which criminals can use the material before victims take precautions.
What customers can do
Affected customers should assume targeted phishing will follow, since attackers hold enough context to make messages convincing. Standard advice applies with extra force here: verify any contact claiming to come from a bank or agency through an independent channel, treat requests for further verification with suspicion, and consider a fresh passport number if the issuing country allows replacement after a documented exposure.
Credit monitoring helps less in this case than usual, because the leaked material points toward identity fraud and physical targeting rather than loan applications. Customers who used Revolut primarily for bitcoin purchases should review whether their transaction history reveals recurring patterns, such as regular purchases tied to payday dates, that could be used to infer balances and timing.
Revolut says systems and funds were unaffected and that it has since hardened its request-handling process. The company built its reputation on fast onboarding and frictionless verification. This incident shows the cost of that speed when the process meets a patient, well-resourced adversary with a real government domain in hand.
