Revolut Ltd. admitted that it unintentionally supplied passports, selfies, home addresses and Bitcoin transaction records to a fraudulent request that appeared to come from a government agency. The breach, reported by multiple crypto and mainstream outlets, affected a “limited” set of customers and did not result in any loss of funds.

Breach details

According to the fintech firm, the request arrived in an email that used the official domain of a state authority, leading internal teams to treat it as legitimate. The correspondence asked for “customer KYC (Know‑Your‑Customer) documentation and full crypto transaction histories,” which Revolut then transmitted to the sender. The company later discovered the request was a spoof, prompting an internal investigation and a public acknowledgment of the incident.

Several outlets, including CoinDesk and Decrypt, noted that the data handed over comprised scanned passports, facial‑recognition selfies and residential details, in addition to on‑chain Bitcoin activity. Revolut said no customer funds were compromised.

“We have identified a breach that resulted from a fraudulent information request. No financial assets were taken, but personal identification and transaction data were disclosed,” Revolut said in a statement.

Impact on crypto users

The exposure of Bitcoin transaction histories is particularly sensitive for users who rely on pseudonymity. On‑chain analyst ZachXBT, cited by The Block, suggested the attackers may have been targeting high‑net‑worth individuals, given the depth of the data requested. However, no concrete evidence of selective targeting has been publicly confirmed.

Customers who received the email request are urged to monitor their accounts for any suspicious activity and to consider tightening security settings, such as enabling two‑factor authentication. Industry observers stress that while the breach did not involve theft, the revelation of transaction patterns could be used for phishing or black‑mail campaigns.

Revolut Premium Visa Infinite Card Midnight Blue
Revolut Premium Visa Infinite Card Midnight Blue (Image: Wikimedia Commons)

Regulatory and market implications

The incident arrives at a time when regulators worldwide are tightening oversight of crypto‑related services. KYC compliance is a cornerstone of anti‑money‑laundering (AML) frameworks, and the breach underscores the challenge of balancing regulatory cooperation with data protection. Financial‑technology firms are under increasing pressure to verify the authenticity of government requests without exposing sensitive user data.

Crypto markets have reacted modestly, with Bitcoin’s price remaining largely unchanged in the immediate aftermath. Analysts note that the episode may fuel broader concerns about the security of custodial services that bridge traditional finance and digital assets. As more users turn to platforms like Revolut for crypto trading, the industry’s ability to safeguard personal and transaction data will remain a focal point for investors and regulators alike.

Revolut has pledged to review its verification procedures, enhance staff training on phishing threats, and cooperate with law‑enforcement agencies to trace the source of the spoofed email. Users are advised to stay alert for further communications from the company and to verify any future government‑related requests through independent channels.

Market Snapshot

AssetPrice24hMarket Cap
Bitcoin BTC$77,131-0.04%$1549.1B
Ethereum ETH$2,520-0.83%$307.5B
BNB BNB$726.35+0.35%$96.8B
XRP XRP$1.36+0.82%$85.7B
Solana SOL$101.55+0.41%$59.6B
Dogecoin DOGE$0.0848+0.82%$13.2B
Cardano ADA$0.207+1.32%$7.8B

Live data: CoinGecko — 2026-09-12 19:22 UTC