TechNewsReel
Live

Revolut Leaks KYC and Bitcoin Data via Fraudulent Government Request

Attackers used a compromised government email domain to trick the fintech giant into releasing sensitive identity and financial records.

TechNewsReel Newsroom · September 14, 2026

Revolut has disclosed a significant data security incident in which sensitive customer information was released to attackers impersonating a government agency. The breach, confirmed by the company on Saturday, September 12, 2026, highlights a critical failure in the verification of official data requests.

The attackers executed a sophisticated social-engineering operation by using an unauthorized email account hosted on a legitimate government agency domain. Because the email originated from a trusted domain and passed Revolut's authentication checks, the company fulfilled fraudulent requests for user data. The leaked information is extensive, including full names, dates of birth, occupations, phone numbers, and postal and email addresses. Most critically, the breach exposed high-value identity documents, including copies of passports and driver's licenses, alongside identity-verification selfies.

Financial records were also compromised, with leaked data including IBANs, account statements, and withdrawal records. Notably, the breach included comprehensive Bitcoin transaction histories for a limited number of users. While Revolut confirmed that its core systems remained secure and customer funds were not compromised, the nature of the leaked data suggests a targeted operation. On-chain investigator ZachXBT and the public notification of former Mt. Gox CEO Mark Karpelès indicate that the breach appeared to specifically target high-net-worth users.

The Vulnerability of Trust

This incident occurred during a pivotal expansion phase for Revolut, coming shortly after the firm launched its EURR stablecoin in August 2026 and received conditional approval for a U.S. national bank charter in September 2026. The breach exposes a systemic vulnerability in how fintechs handle government inquiries: relying on domain authentication alone is insufficient if the individual account sending the request is unauthorized or compromised.

Implications for Crypto Privacy

The intersection of government-grade identity documents and detailed Bitcoin transaction logs creates a severe security risk. By linking real-world identities (KYC) to specific blockchain histories, attackers can effectively deanonymize crypto holders. This allows for the creation of highly convincing social-engineering lures, increasing the risk of targeted phishing, identity theft, and extortion for the affected affluent users.

What's Next

Industry observers are now watching whether other fintechs utilize similar automated or trust-based verification for government requests. While the immediate technical breach is contained, the long-term risk for the affected users remains high due to the permanent nature of the leaked identity documents. It remains to be seen if Revolut will implement more rigorous, multi-channel verification for official data requests to prevent similar impersonation attacks.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.