Revolut confirmed on Thursday that it inadvertently transmitted passport copies and full Bitcoin transaction histories of a limited group of customers after complying with a fraudulent information request that appeared to originate from a government agency’s email domain. The breach was discovered during an internal audit and has prompted the firm to launch a security review.
How the breach unfolded
According to multiple reports, the request arrived in Revolut’s compliance inbox from an address that used a legitimate government domain, leading staff to believe it was a bona‑fide law‑enforcement inquiry. The company’s standard verification procedures did not flag the email as suspicious, and the requested documents – including passports and other Know‑Your‑Customer (KYC) files – were supplied alongside the users’ complete Bitcoin transaction logs.
"Revolut handed over passports and full Bitcoin transaction histories to a fake government email," reported 24/7 Wall St.
The data handed over linked cryptocurrency wallet addresses to the owners’ residential addresses, effectively tying on‑chain activity to real‑world identities. The exact number of affected customers has not been disclosed, though the firm described the set as “limited.”
Implications for crypto users and fintech
On‑chain analyst ZachXBT, cited by The Block, speculated that the incident may have been aimed at high‑net‑worth individuals whose crypto holdings are sizable enough to attract sophisticated phishing campaigns. By exposing transaction histories, the breach could potentially aid illicit actors in tracing and targeting valuable assets.
For crypto‑native readers, the leak underscores the inherent tension between blockchain’s pseudonymous nature and the growing demand for stringent KYC compliance from regulators and financial institutions. Mainstream audiences should note that such data exposure can erode privacy protections that many users assume when transacting on public ledgers.
Regulatory backdrop and industry response
The episode arrives amid intensified global scrutiny of crypto services, with governments in the United States, Europe and Asia tightening AML and KYC obligations. Fintech firms that bridge traditional banking and digital assets, like Revolut, are under pressure to demonstrate robust verification processes while safeguarding user privacy.
Security experts highlighted that the use of a genuine government domain in the phishing email helped the request bypass Revolut’s internal safeguards. Security Affairs reported that the fraudulent email passed “multiple security checks,” exposing gaps in the firm’s email‑authentication protocols.

Revolut has urged any customer who may have been affected to monitor their accounts for suspicious activity, consider changing passwords, and enable two‑factor authentication. The company also pledged to cooperate with law‑enforcement agencies and to refine its verification workflow to prevent similar incidents.
Industry observers warn that the breach could prompt a broader re‑examination of how fintech platforms handle KYC data linked to blockchain activity. As regulators continue to demand greater transparency, firms may need to balance compliance with enhanced encryption and data‑minimisation strategies to protect user anonymity.
Market Snapshot
| Asset | Price | 24h | Market Cap |
|---|---|---|---|
| $77,261 | -0.10% | $1551.6B | |
| $2,523 | +0.33% | $307.9B | |
| $728.36 | -0.13% | $97.0B | |
| $1.36 | +0.28% | $85.8B | |
| $101.86 | -0.27% | $59.8B | |
| $0.0848 | +0.41% | $13.2B | |
| $0.207 | +0.18% | $7.8B |
Live data: CoinGecko — 2026-09-13 01:21 UTC