Revolut has confirmed that an unauthorized third party obtained sensitive customer records by submitting fraudulent data requests from a legitimate government agency email domain, exposing identity documents and Bitcoin transaction activity. The London-based fintech disclosed the incident on Saturday, September 12, 2026, and said a “limited” number of its more than 80 million customers were affected.
According to notifications reviewed by TechCrunch, the exposed information included birth dates, postal and email addresses, phone numbers, copies of passports and driver’s licenses, verification selfies, account statements, and transaction histories. On-chain investigator ZachXBT published additional details from the notice, including IBANs, withdrawal records, occupations, and transaction history covering Bitcoin. He assessed the breach as limited in scale and aimed at high-net-worth users.
Revolut characterized the episode as a sophisticated external impersonation scam, not a technical exploit. The attacker used an address on a genuine government domain, and the fraudulent request cleared the company’s checks before it was detected. “Revolut systems and customer funds are unaffected,” a spokesperson said. The company blocked the sender, notified the relevant government agency, law enforcement, data protection authorities, and financial regulators, and contacted affected customers directly.
Threat actors allegedly behind the breach are now demanding a 10,000 BTC ransom and threatening to leak stolen customer data, according to posts amplified by Coin Bureau. They have reportedly begun publishing information belonging to high-profile clients.
The incident highlights a significant privacy risk for crypto users at mainstream financial platforms. Bitcoin’s blockchain records transactions publicly, but personal identifiers such as passports, home addresses, and contact details normally remain off-chain. When a financial intermediary discloses identity documents alongside Bitcoin transaction histories, those datasets can be linked to create a detailed picture of an individual’s financial activity. Crypto commentator Mert argued the case shows KYC processes should “be made literally illegal to do anything but ZK-based KYC” if KYC must be done.
Revolut has not disclosed the exact number of affected customers, the specific market involved, or which government agency’s domain was misused. The company also has not stated that crypto holders or wealthy customers were specifically targeted. The breach follows other security incidents affecting crypto-adjacent services, including the LayerZero executor wallet breach that drained $2.4 million earlier this year, and comes as Revolut expands its crypto footprint across the EU and moves to delist USDT ahead of the MiCA deadline.