Loading article…
Revolut confirmed a data breach after attackers used spoofed government emails to access records of 680 customers, including crypto transaction histories.
Revolut has confirmed that an external impersonation scam resulted in the unauthorized disclosure of sensitive customer data, including identity documents and Bitcoin transaction histories, after attackers successfully spoofed a legitimate government agency’s email domain [1, 2]. While the fintech firm maintains that its internal systems remain secure and no customer funds were accessed, the incident exposes a critical vulnerability in how financial institutions verify legal-compliance requests [2, 3].
| At a glance | |
|---|---|
| Affected customers | ~680 |
| Incident type | External impersonation scam |
| Data exposed | Identity docs, IBANs, crypto history |
| Status | Systems secure, funds untouched |
The incident began when an unauthorized party, operating from an email address on a genuine government domain, submitted requests for customer information that passed standard domain authentication checks [2]. Revolut staff processed these as routine legal-compliance requests, inadvertently releasing data for approximately 680 customers [2]. The disclosed information includes full names, dates of birth, home addresses, phone numbers, and copies of passports or driving licenses [2].
Beyond basic contact details, the breach extended to financial and digital asset records. Affected files included account statements, IBANs, and full transaction histories, which reportedly contained specific records of Bitcoin activity [1, 2]. While Revolut noted that no biometric facial telemetry data was involved, the exposure of verification selfies and identity documents creates a heightened risk for targeted impersonation and social engineering [2].
The exposure of linked financial and identity data poses a specific threat to crypto users, as it bridges the gap between anonymous on-chain activity and real-world identities [2]. By connecting specific Bitcoin transaction histories to verified documents and residential addresses, the leaked data allows for the monitoring of future large transfers by individuals who already possess the user's personal information [2].
This incident follows a pattern of social engineering attacks against major platforms, including previous data leaks at Apple, Meta, and Discord, where attackers used forged emergency requests to obtain user information [2]. Although Revolut has blocked the fraudulent email address and notified law enforcement and financial regulators, reports on Telegram claim that a group is now leaking files purportedly belonging to VIP clients, allegedly demanding a ransom of 10,000 Bitcoin [1, 2]. Revolut has not confirmed the authenticity of these files or the ransom demand [2].
The core issue remains the "seam" in institutional compliance: the legal obligation to respond to official requests creates a channel that, if compromised, allows attackers to bypass internal security systems entirely [2]. Whether this incident leads to a broader industry shift in how banks authenticate sensitive data requests remains the primary open question for the fintech sector [2, 3].
Coverage is mostly measured — 217 of 219 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 3 outlets · Sep 16, 2026 · How we report
A pig butchering Crypto Scam is a fraudulent scheme where perpetrators cultivate romantic or investment relationships with victims over weeks or months. Once trust is established, the fraudsters convince the victims to transfer funds into fake investment platforms.
As of September 9, 2026, the Scam Center Strike Force restrained approximately $52 million in laundered assets in a single day. This operation targeted the Xinbi Guarantee marketplace and contributed to a cumulative total of $938 million in frozen or seized assets since the task force launched in November 2025.
Revolut confirmed that no customer funds were touched during the data disclosure incident identified on September 11, 2026. The company stated that the breach involved the unauthorized release of customer identity and transaction data due to a sophisticated external impersonation scam.