Exchange Risk Intelligence

Revolut Data Breach Exposes Bitcoin History and Identity Records via Forged Government Request

According to reporting by CryptoTicker and CoinDesk, digital asset service provider Revolut experienced a significant data security incident on September 11 and September 12, 2026. An unauthorized external entity exploited a verified government email domain to submit a fraudulent emergency information request, leading to the unauthorized disclosure of customer identification documents, account statements, and comprehensive Bitcoin transaction records. Revolut stated that core system access and user funds remained unaffected, while investigators noted that a targeted circle of users was impacted. These claims, however, are not officially confirmed by independent regulatory authorities.

Digital security risk concept showing data breach and exposed crypto transaction history
Image: CryptoTicker

Nature of the Incident and Data Handover

According to the reporting published by CryptoTicker, digital asset service provider Revolut experienced an unusual security compromise on September 11 and September 12, 2026. Rather than involving a malicious software deployment or a traditional server infrastructure breach, the incident materialized through social engineering and domain impersonation. An unauthorized third party successfully submitted a fraudulent emergency information request utilizing the genuine, authenticated email domain of a legitimate government agency. Trusting the origin domain, Revolut personnel treated the communication as a lawful administrative mandate and inadvertently released confidential customer files.

The disclosed records included critical KYC documentation such as passport scans, driver's licences, verification selfies, and residential addresses, alongside comprehensive financial information. Most notably, the compromised package incorporated full account statements, withdrawal logs, and complete historical transaction records for Bitcoin activity associated with the targeted users. Although company representatives maintained that core internal systems, password credentials, and customer funds remained entirely untouched, the unauthorized release of deep transaction data established a significant privacy compromise for the affected individuals.

Mechanism of the Fraudulent Request

The breach exposed structural vulnerabilities inherent in processing urgent law enforcement and regulatory data inquiries. Emergency data request procedures exist within financial institutions to ensure rapid cooperation during critical public safety emergencies, often bypassing standard bureaucratic verification steps. In this instance, the bad actor either gained unauthorized access to an official government mailbox or established a fraudulent user account directly within the agency's domain infrastructure. Because compliance personnel are specifically trained to respond promptly to public authorities, the urgent tone and official origin domain sufficed to override standard scrutiny.

This sophisticated vector bypassed conventional technical safeguards like Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication, Reporting, and Conformance. These cryptographic protocols confirm that an email genuinely originates from the stated domain name and has not been altered in transit, but they fail entirely to verify whether the individual operating the specific mailbox possesses legitimate authorization. Consequently, relying solely on domain validation proved fatal, demonstrating that passed technical authentication does not equate to verified operational authority.

Risks Posed by Exposed Bitcoin Histories

For cryptocurrency holders, the inclusion of complete Bitcoin transaction histories within the leaked data package represents the most hazardous element of the incident. Unlike identity documents or telephone numbers that can theoretically be managed through increased vigilance, historical blockchain transactions reside within a permanent, immutable public database. Anyone possessing a user's complete ledger of deposits, withdrawals, timestamps, and amounts gains the foundational raw material required to perform sophisticated cluster analysis on the public ledger.

Cluster analysis enables external parties to link multiple distinct cryptocurrency addresses to a single economic entity based on shared transactional inputs and patterns. Once a provider withdrawal log supplies the crucial anchoring point connecting an anonymous address cluster to a real-world identity, the veil of blockchain pseudononymity vanishes permanently. The attacker can accurately gauge total holdings, monitor ongoing asset movements, and combine this financial intelligence with home addresses and identification photos to orchestrate targeted physical extortion or violent home-invasion robberies.

Verification and Defensive Protocols

Affected account holders must rely on methodical, verified channels rather than speculation or unsolicited digital correspondence to determine their exposure status. Revolut reportedly dispatched individual notifications to impacted customers, prompting users to check their internal application inboxes directly rather than clicking external email links. Additionally, individuals should exercise their legal rights by submitting a formal Article 15 General Data Protection Regulation subject access request, demanding explicit written confirmation from the institution regarding the exact recipients of their personal data.

In response to the follow-up threat landscape, users must adopt comprehensive defensive postures against sophisticated phishing attempts that incorporate leaked personal details. Because attackers now possess genuine account movements and home addresses, fraudulent communications will exhibit an alarming level of credibility. Account security must be reinforced by implementing strict internal withdrawal confirmations, rejecting telephone inquiries from purported staff members on principle, and migrating surplus digital asset holdings into secure self-custody solutions with robust hardware safeguards.

Conclusion and Regulatory Findings

In conclusion, the risk intelligence investigation establishes that Revolut experienced a significant operational data exposure on September 11 and September 12, 2026, driven by a fraudulent emergency request utilizing a compromised government email domain. The affected user group comprises an undisclosed circle of international account holders whose KYC files, account statements, and comprehensive Bitcoin transaction histories were improperly handed over to an unauthorized third party. What is officially reported includes the compromise of verification documents and blockchain activity, while the total number of victims and the identity of the rogue agency account remain not officially confirmed by independent oversight bodies.

As an immediate next action, affected customers must check their inboxes within the proprietary application, file an Article 15 GDPR disclosure request, and systematically transfer excess cryptocurrency holdings into secure self-custody wallets after establishing reliable backup procedures. This incident underlines that platform security depends as heavily on administrative response verification as it does on network infrastructure. Cexvia will continue monitoring supervisory updates from European data protection authorities regarding this evolving regulatory compliance failure.

Cexvia conclusion

Incident Conclusion and Verification Summary

The investigation by CryptoTicker reveals that Revolut inadvertently disclosed sensitive customer verification materials and complete Bitcoin transaction histories to an unauthorized third party following a sophisticated email domain impersonation. Affected users comprise a limited circle of account holders whose personal data and crypto activity were exposed. This operational security failure highlights vulnerabilities in handling emergency legal requests, and the details regarding the full extent of the breach remain not officially confirmed.

Risk meaning
The compromise of comprehensive Bitcoin transaction histories alongside government-issued identity documents creates profound long-term privacy and physical security hazards. Attackers can leverage the disclosed transaction amounts and timestamps to perform cluster analysis, linking anonymous blockchain addresses directly to real-world residential addresses and legal identities. This exposure elevates the risk of targeted physical extortion and advanced phishing campaigns against affected account holders.
User action
Account holders must immediately verify whether they received an official notification within the proprietary mobile application and submit an Article 15 General Data Protection Regulation subject access request to confirm data disclosure status. Users should transition excessive balances into self-custody solutions equipped with robust backup strategies, maintain extreme skepticism regarding any direct communications referencing account history, and monitor credit files for unauthorized activity.
Lithuanian Data Protection Authority / ECB