Revolut leaks sensitive customer data after fraudulent request from government domain

Revolut has inadvertently disclosed personal data of customers, including passport copies, selfies for verification, and complete Bitcoin transaction histories, after responding to a fraudulent request apparently from a government agency. The attack, described by the company as "a sophisticated external impersonation scam," targeted a limited number of users, although Revolut did not specify how many customers were affected nor revealed the name of the impersonated agency.

Quick Answer

The breach occurred due to an advanced phishing attack that exploited a legitimate email domain of a government agency. The exposed data includes identity information, contact details, verification documents, and financial details, including Bitcoin transactions. Revolut stated that customer systems and funds were not compromised.

Technical details of the breach

According to crypto investigator ZachXBT, Revolut received an information request that appeared to come from a government agency, sent from an unauthorized but official-agency domain email account. The request included valid domain authentication credentials, which led Revolut to consider it legitimate. The exposed data included full names, dates of birth, occupations, postal addresses, emails, phone numbers, passport or driver's license copies, and verification selfies.

For cryptocurrency holders, the exposed financial data was particularly concerning: it included bank statements with IBAN numbers and wallet references, withdrawal logs, and complete transaction histories, including Bitcoin. Revolut specified that no facial telemetry biometric data was involved.

Revolut's reaction and security implications

A Revolut spokesperson confirmed the breach to TechCrunch, describing it as a "sophisticated external impersonation scam where an unauthorized third party used a legitimate email domain of a government agency to send fraudulent information requests." The company stated that it had blocked the involved email address, notified the agency, law enforcement, and regulators, and ensured that customer systems and funds were not compromised.

ZachXBT noted that the incident seems to have targeted high-net-worth individuals, a significant concern given the recent wave of violent "wrench attacks" against known cryptocurrency holders. These physical, often violent attacks aim to gain access to victims' crypto funds.

Criticism of KYC compliance and industry context

The breach has sparked criticism on social media, with users arguing that the episode demonstrates how Know-Your-Customer (KYC) norms have created risks without significant benefits. Marc Zeller, a Revolut user, tweeted: "I woke up with all my data leaked by [@Revolut]. Clear reminder that KYC has not produced significant benefits and has put many in danger."

This breach comes at a difficult time for companies handling personal data of crypto users. Recently, hardware wallet manufacturer Trezor suffered a breach by a support provider, exposing tens of thousands of additional customers. X also seems to have suffered a data breach that flooded users with password reset requests.

Future prospects for Revolut

Revolut, which launched its euro-backed stablecoin EURR this year, is currently evaluating an initial public offering (IPO). The company will have to address the repercussions of this breach while proceeding with its expansion plans. The breach underscores the importance of identity management and protection of sensitive data in an ever-evolving threat landscape.

For companies operating in the crypto sector, this breach serves as a warning about the importance of implementing robust MDR services and Security Information and Event Management solutions to prevent similar incidents. Additionally, the need for adequate cyber insurance is more critical than ever to mitigate the financial risks associated with such breaches.

The impact of the breach on the cryptocurrency sector

This incident comes amid growing concerns about data security in the cryptocurrency sector. According to Chainalysis, over $30 million was stolen in 2026 through physical attacks known as "wrench attacks," where criminals directly target individuals to gain access to their digital wallets. The disclosure of sensitive information such as IBAN numbers and wallet references significantly increases the risk that these users will become targets of such attacks.

The challenges of regulatory compliance

The breach raises critical questions about the effectiveness of compliance protocols, particularly Know-Your-Customer (KYC) and Anti-Money Laundering (AML) regulations. While these regulations are designed to prevent money laundering and other illegal activities, this incident demonstrates how they can also create vulnerabilities. Companies must carefully balance the need to collect personal data for compliance with protecting such information from unauthorized access.

The importance of training and awareness

An often-overlooked aspect of cybersecurity is continuous employee training. This incident underscores the importance of advanced training programs for employees, particularly those involved in managing requests for sensitive data. Implementing phishing simulations and other practical exercises can help prevent future similar incidents.

Implications for crypto users

For Revolut users and other crypto platforms, this incident serves as a reminder of the importance of adopting proactive security measures. These include using hardware wallets to store cryptocurrencies, implementing two-factor authentication, and regularly reviewing suspicious transactions. Additionally, users should consider monitoring their personal data through dark web monitoring services.

The role of cyber insurance

In an ever-evolving threat landscape, cyber insurance is becoming an essential element for companies handling sensitive data. These policies can cover the costs associated with incident response, victim notification, and reputation management. For companies like Revolut, investing in adequate coverage can significantly mitigate the financial risks associated with data breaches.

Future prospects for cryptocurrency security

As the cryptocurrency sector continues to grow, it is likely that security threats will also evolve. Companies must remain proactive, adopting advanced technologies such as artificial intelligence for threat detection and implementing robust security protocols. Additionally, collaboration between companies, regulators, and law enforcement will be crucial to addressing emerging security challenges.

The evolution of regulations and best practices

This incident could accelerate the evolution of regulations and best practices in the cryptocurrency sector. Regulatory authorities may require stricter security standards for platforms handling sensitive data, while companies may voluntarily adopt more stringent protocols to protect their users. The NIS2 directive and the DORA regulation, which aim to improve digital operational resilience, could become benchmarks for companies operating in this sector.

Opportunities for advanced security solutions

For cybersecurity companies, this incident represents an opportunity to develop advanced solutions that can prevent similar breaches. Technologies such as Managed Detection and Response (MDR) systems and Security Information and Event Management (SIEM) platforms can play a crucial role in detecting and mitigating threats in real-time. Additionally, Data Loss Prevention (DLP) solutions can help protect sensitive data from unauthorized access.

The need for greater transparency

Finally, this incident underscores the importance of transparency from companies handling sensitive data. Providing clear and timely information to affected users can help rebuild trust and mitigate reputational damage. Companies should adopt a proactive approach to communication, informing users about the steps they are taking to address the breach and prevent future incidents.

Towards a safer future

As the cryptocurrency sector continues to evolve, data security remains a critical priority. This incident serves as a warning for companies and users, emphasizing the importance of adopting robust security measures and remaining proactive in the face of emerging threats. With the adoption of advanced technologies, collaboration among stakeholders, and the implementation of stringent regulations, the sector can move towards a safer and more resilient future.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.