Overview
- Revolut has inadvertently released sensitive customer information, including passport copies and complete Bitcoin transaction records, after responding to a fraudulent request that masqueraded as an official government communication.
- A spokesperson from Revolut characterized the incident as "a sophisticated external impersonation scam," indicating that only a "limited" number of customers were impacted. They assured that the company's systems and customer funds remained secure but did not disclose specific numbers or identify the agency involved.
- Crypto investigator ZachXBT noted that the breach seemed to focus on high-net-worth individuals, raising concerns about potential "wrench attacks" in light of similar recent incidents.
In a troubling incident, fintech leader Revolut mistakenly shared sensitive customer data, such as passport copies and Bitcoin transaction histories, with a malicious entity after being deceived by a fraudulent request disguised as a legitimate inquiry from a government agency.
According to a notification sent to customers by crypto analyst ZachXBT, Revolut acted on a request for customer information that appeared to originate from a government agency, which was sent from an unauthorized email address that utilized the agency's official domain.
Myriad: What’s Bitcoin's next move? Share your prediction.The fraudulent message included valid domain authentication credentials, leading Revolut to believe it was a legitimate request and to subsequently fulfill it.
The compromised data was extensive, including personal identity information such as full name, birth date, and occupation; contact details like address, email, and phone number; and verification documents including passport copies and selfies used for identity verification.
Of particular concern to cryptocurrency holders, the leaked financial data encompassed account statements featuring IBAN and wallet reference numbers, records of withdrawals, and complete transaction histories related to Bitcoin. However, Revolut clarified that no biometric facial data was compromised.
A representative from Revolut confirmed the data breach to TechCrunch, describing it as "a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information."
The company indicated that a "limited" number of customers were affected, that it had blocked the fraudulent email address, and that it had notified the agency, law enforcement, and regulatory bodies. Revolut did not disclose how many individuals were impacted or which agency was impersonated.
According to ZachXBT, the breach appeared to target affluent users, which is concerning given the rise in violent "wrench attacks" aimed at known cryptocurrency holders. The incident has drawn significant backlash, with many users on social media expressing that the situation highlights the risks associated with know-your-customer regulations, which they believe have not yielded meaningful benefits.
Woke up to all my data leaked by @Revolut.
Sharp reminder that KYC hasn’t produced meaningful upside and has put many in harm’s way. pic.twitter.com/RimOBQr7DW
— Marc Zeller (@mzeller) September 12, 2026
This breach occurs during a challenging period for companies that manage personal data for crypto users. Recently, hardware wallet manufacturer Trezor experienced a support vendor breach that exposed tens of thousands more customers, and X also appeared to suffer a data breach that led to a flood of password reset requests for users.
Revolut, which recently launched a euro-pegged stablecoin called EURR, is currently considering an initial public offering (IPO).
