Revolut Data Breach Exposes Bitcoin Activity as Attackers Demand 10,000 BTC Ransom

1 hour ago 4 sources negative

Key takeaways:

  • Revolut breach highlights KYC data concentration risk, boosting demand for ZK-based identity in crypto.
  • Linking Bitcoin transaction histories to leaked IDs raises chain-analysis risk, pressuring high-net-worth BTC holders' privacy.
  • Ransom demand signals attackers value KYC-linked Bitcoin data, elevating regulatory scrutiny for custodial platforms.

Revolut has confirmed that an unauthorized third party obtained sensitive customer records by submitting fraudulent data requests from a legitimate government agency email domain, exposing identity documents and Bitcoin transaction activity. The London-based fintech disclosed the incident on Saturday, September 12, 2026, and said a “limited” number of its more than 80 million customers were affected.

According to notifications reviewed by TechCrunch, the exposed information included birth dates, postal and email addresses, phone numbers, copies of passports and driver’s licenses, verification selfies, account statements, and transaction histories. On-chain investigator ZachXBT published additional details from the notice, including IBANs, withdrawal records, occupations, and transaction history covering Bitcoin. He assessed the breach as limited in scale and aimed at high-net-worth users.

Revolut characterized the episode as a sophisticated external impersonation scam, not a technical exploit. The attacker used an address on a genuine government domain, and the fraudulent request cleared the company’s checks before it was detected. “Revolut systems and customer funds are unaffected,” a spokesperson said. The company blocked the sender, notified the relevant government agency, law enforcement, data protection authorities, and financial regulators, and contacted affected customers directly.

Threat actors allegedly behind the breach are now demanding a 10,000 BTC ransom and threatening to leak stolen customer data, according to posts amplified by Coin Bureau. They have reportedly begun publishing information belonging to high-profile clients.

The incident highlights a significant privacy risk for crypto users at mainstream financial platforms. Bitcoin’s blockchain records transactions publicly, but personal identifiers such as passports, home addresses, and contact details normally remain off-chain. When a financial intermediary discloses identity documents alongside Bitcoin transaction histories, those datasets can be linked to create a detailed picture of an individual’s financial activity. Crypto commentator Mert argued the case shows KYC processes should “be made literally illegal to do anything but ZK-based KYC” if KYC must be done.

Revolut has not disclosed the exact number of affected customers, the specific market involved, or which government agency’s domain was misused. The company also has not stated that crypto holders or wealthy customers were specifically targeted. The breach follows other security incidents affecting crypto-adjacent services, including the LayerZero executor wallet breach that drained $2.4 million earlier this year, and comes as Revolut expands its crypto footprint across the EU and moves to delist USDT ahead of the MiCA deadline.

Previously on the topic:
Sep 12, 2026, 9:14 a.m.
Revolut Data Breach Exposes Passports and Bitcoin Transaction Records
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.