Revolut has disclosed a data breach in which sensitive customer information—including passport copies, identity verification selfies and complete Bitcoin transaction histories—was handed to an unauthorized third party through a sophisticated email impersonation scheme.
According to reporting by Decrypt, the fintech platform received a fraudulent data request that appeared to originate from a legitimate government agency email domain. The request carried valid domain authentication credentials, prompting Revolut to fulfill it without detecting the deception. The company confirmed the incident to TechCrunch as “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests.”
Revolut declined to specify how many customers were affected or name the agency involved. A company spokesperson said a “limited” number of users were impacted, that systems and customer funds remained secure, and that the unauthorized email address had been blocked.
The Scope of Exposed Data
The breach exposed an unusually comprehensive set of personal and financial details. Affected customers had their full names, dates of birth, occupations, postal addresses, email addresses and phone numbers compromised. Identity verification documents—including passport or driver’s license copies and selfies submitted for KYC purposes—were also included in the leaked data.
Most concerning for crypto users was the financial data component. The exposed records contained account statements with IBAN and wallet reference numbers, withdrawal records and complete Bitcoin transaction histories. Revolut said biometric facial telemetry data was not involved.
The disclosure of full transaction histories presents particular risks. Combined with passport data and verified identity information, this material could enable targeted attacks against known crypto holders or facilitate social engineering campaigns.
High-Net-Worth Targeting Raises Security Concerns
Crypto investigator ZachXBT highlighted that the breach appeared to target high-net-worth individuals, a pattern consistent with an uptick in violent “wrench attacks”—physical assaults targeting known cryptocurrency holders to coerce asset transfers.
The incident underscores the security paradox facing crypto users. Know-your-customer regulations mandate the collection and storage of sensitive identity data under the premise of preventing financial crime. Yet this centralized repository of verified personal information linked to crypto holdings creates exactly the kind of target high-value attackers seek.
Social media criticism of Revolut’s handling of the breach reflected broader frustration with KYC frameworks. Several users argued the episode demonstrates that mandatory identity verification imposes security costs on users without proportionate regulatory or consumer protection benefits.
A Broader Pattern of Fintech Data Incidents
The Revolut breach arrives amid a challenging period for cryptocurrency-adjacent companies handling user data. Hardware wallet manufacturer Trezor disclosed a support vendor breach that ultimately exposed tens of thousands of additional customers. Social media platform X also disclosed a data breach that triggered widespread password reset notifications.
The timing matters for Revolut specifically. The company launched its euro-pegged EURR stablecoin this year and is currently evaluating an initial public offering. Data security incidents typically create friction in IPO preparations, as institutional investors and underwriters scrutinize a company’s data governance and breach response capabilities.
Revolut said it had notified law enforcement, relevant regulators and the impersonated government agency. The company’s response to the incident—including whether it implements additional verification procedures for government data requests—will likely factor into institutional and regulatory assessment of the platform ahead of any public markets debut.