Revolut has confirmed that it mistakenly handed over sensitive customer data — including passports, driving licenses, home addresses, bank statements, identity-verification selfies and Bitcoin transaction records — to fraudsters who impersonated a government agency using a hijacked but legitimate official email domain. The breach, disclosed around September 12, 2026, underscores a growing danger in digital finance: it is no longer just servers and passwords that need defending, but the trust placed in official-looking correspondence.
According to the fintech, the attackers did not breach Revolut’s own systems. Instead, they gained access to a government agency’s email infrastructure and used it to send a request for customer information that appeared entirely legitimate, complete with valid credentials. Revolut says a ‘limited number’ of customers were affected, though it has not specified how many, nor which country’s government agency was impersonated, citing an ongoing police investigation.
A Trusted Channel Turned Against Its Users
The mechanics of the incident are what make it unusual. Financial institutions routinely comply with legitimate requests from law enforcement and regulators, and they typically rely on the authenticity of the sending domain and credentials as proof of legitimacy. In this case, that verification layer itself was compromised. The email came from a real government domain, not a spoofed lookalike, which means the standard checks that compliance teams use to filter out phishing attempts would likely have passed.
Revolut says that core account security — login credentials, passcodes, biometric facial templates and customer funds — was not compromised. However, the actual verification photos submitted by customers during onboarding, along with financial and identity documents, were sent to the fraudulent requester. The company says it has since notified the impersonated agency, alerted police, informed data protection and financial regulators, and blocked the sender responsible for the request.
The leak was first flagged publicly by blockchain investigator ZachXBT, who noted that the exposed data appeared to target a small group of wealthy users rather than a broad customer base. That detail changes the risk calculus considerably. A mass data leak is a numbers game for criminals; a narrow, targeted one suggests the attackers already had a shortlist of high-value individuals in mind, likely selected because their Bitcoin transaction histories signaled substantial holdings.
Why Crypto Holders Face a Sharper Risk
What separates this incident from a routine data-privacy failure is the inclusion of Bitcoin transaction records alongside passports, home addresses and bank statements. Combined, that dataset does more than enable financial fraud — it can identify who owns significant crypto wealth and where they live. Security researchers have long warned that on-chain transparency, paired with leaked personal identifiers, creates a roadmap for so-called ‘$5 wrench attacks,’ where criminals pursue victims physically rather than digitally, precisely because crypto holdings, unlike bank deposits, cannot be frozen or clawed back through a central authority.
That risk is part of a broader pattern in which crypto’s technical strengths — self-custody, irreversibility, pseudonymous but traceable ledgers — become liabilities the moment personal identity is attached to a wallet. Institutional-grade custody arrangements, of the kind sought through a national trust bank charter for crypto custody, exist partly to insulate large holders from exactly this kind of exposure. Individual retail users verifying their identity with an exchange rarely have that layer of protection.
The episode also illustrates how regulatory and compliance infrastructure, meant to protect consumers, can become an attack surface. As authorities across jurisdictions increase scrutiny of crypto-linked platforms — from prediction markets operating without authorization, as ESMA recently flagged in the EU, to tokenized asset schemes drawing regulatory attention — the volume of legitimate data-sharing requests between exchanges, banks and government bodies is only set to grow. Each request is a potential point of failure if the underlying systems it depends on, such as a government email server, are not adequately secured.
What Comes Next
Several open questions will shape how this incident is remembered. Revolut has not disclosed which agency’s domain was compromised, and the ongoing police investigation may keep that detail confidential for some time. Regulators who were notified, including data protection authorities, will likely need to determine whether Revolut’s internal verification procedures for government requests met required standards, and whether new safeguards — such as secondary confirmation channels for sensitive document requests — should become mandatory across the industry.
- Whether Revolut discloses the exact number of affected customers as the investigation progresses.
- Whether the impersonated government agency confirms how its email systems were compromised.
- Whether affected customers report follow-up phishing attempts or fraud using the leaked documents.
- Whether regulators impose new verification requirements on fintechs handling law-enforcement data requests.
For now, the incident serves as a reminder that as crypto custody, tokenized assets and collateralized trading — including cases where a Bitcoin position can be liquidated because of unrelated market stress — become more deeply woven into mainstream finance, the weakest link in the security chain is often not the blockchain itself, but the human and institutional systems built around it.
Source: BeInCrypto
This content is for informational purposes only and does not constitute financial or investment advice.




Create a free account to comment and earn rewards.
Create account Log in