Skip to content

Revolut Tricked by Fake Government Request: Bitcoin History and IDs Exposed

Revolut confirmed it handed identity documents and Bitcoin transaction histories to an unauthorized party after a spoofed government agency request bypassed…

5 min read How we work

Revolut has confirmed that sensitive customer data, including complete Bitcoin transaction histories, was handed over to an unauthorized party after the fintech responded to what appeared to be a legitimate government agency request. The exposed Bitcoin data at Revolut did not leave through a hacked server or a stolen password: the information walked out the front door, delivered by staff who genuinely believed they were complying with a lawful legal demand. No Revolut systems were breached. No customer funds were touched.

This incident deserves careful attention precisely because the problem was not technical. It was organizational. The question at the center of the case was not whether Revolut's encryption held up, but whether the people handling the request could verify that the person asking was actually who they claimed to be.

What Actually Happened

According to Revolut's own confirmation, the company received information requests originating from an email account that operated within the genuine domain infrastructure of a real government agency. This was not a lookalike domain with a subtle typo, the kind of trick that standard email authentication checks are designed to catch. The request passed those technical checks because, from a purely technical standpoint, it genuinely did originate from that domain.

Revolut described the incident as a “sophisticated external impersonation scam.” The company confirmed that only a limited number of customers were affected, but declined to specify how many or which government agency's infrastructure was exploited. That omission appears deliberate: naming the agency would make it easier for other companies to search their own archives for similar messages. Once the anomaly was detected, Revolut blocked the compromised address across all internal systems and notified the real government agency, law enforcement, financial regulators, and the relevant data protection authorities.

What Data Was Exposed

According to the notifications sent to affected customers, the information potentially shared with the unauthorized party includes identity documents, residential addresses, contact details, account statements, international banking coordinates, withdrawal records, and complete transaction histories, including Bitcoin activity. One specific point remains contested: whether biometric selfie data was among the exposed information. Some accounts of the incident include it in the list of exposed data, while Revolut's official customer notification reportedly clarified that no facial biometric data was involved. That detail warrants caution until further clarity emerges.

A well-known blockchain transaction analyst observed that the incident appears to have targeted high-net-worth customers specifically, raising a concern that goes well beyond ordinary digital privacy. The combination of verified real identity, residential address, and a detailed record of cryptocurrency holdings is precisely the profile that feeds what the industry calls “wrench attacks”: physical assaults targeting individuals known to hold significant cryptocurrency wealth. Among those who publicly confirmed they were affected is a former chief executive of a once-prominent crypto exchange, now remembered primarily for its spectacular collapse.

The Revolut Incident: Key Facts

What we know. Source: Revolut, Reuters, 2026

  • Not a hack: no systems were breached. Data was handed over to a party posing as a legitimate authority.
  • What leaked: identity documents, addresses, IBAN details, full transaction history including Bitcoin.
  • The risk: verified identity combined with crypto history creates conditions for targeted phishing and physical attacks.

Not an Isolated Incident

There is a broader context that makes this episode more than an isolated corporate misstep. Just three days before this incident, a major hardware wallet manufacturer confirmed a broadly similar breach in its underlying nature: an account used for official communications had been compromised and used to send a fake security alert to hundreds of thousands of subscribers. That is precisely the pattern we covered when analyzing the false security emails that targeted BitBox and Trezor users.

Timeline of the Revolut and Trezor incidents
Timeline of the Revolut and Trezor incidents

The thread connecting both episodes, despite their different mechanics, is the same: in neither case was cryptographic technology broken. What was exploited was an existing trust channel that users or the companies themselves had taken for granted as secure. The same underlying pattern appeared in other recent incidents we covered, including the suspicious peg-out involving Liquid Network and the exploit affecting six blockchains in the Cosmos ecosystem. It is almost never the underlying cryptography that fails. It is the human and organizational processes built around it.

Security incident at Brevo, our third-party email provider
Trezor's third-party marketing e-mail provider, Brevo has been breached in an attack. Trezor has quickly taken down the domain and is investigating the situation.

What to Do If You Were Affected

If you use Revolut and are concerned about whether your data was involved, check directly through the official Revolut app or website. Don't click any links arriving by email that claim to address the incident: in the days following a breach of this kind, fraudsters routinely exploit the resulting confusion to launch secondary phishing campaigns using the very anxiety the breach created.

For anyone holding significant cryptocurrency wealth whose identifying data may now be linked to their digital assets in unauthorized hands, concrete precautions are worth taking on both the physical and digital security front. Be alert to communications that use real personal details to appear credible. Understand that once information of this kind is out, it cannot be recalled. Our guide on how to protect your cryptocurrency holdings covers the right custody practices in detail.

The Wider Picture

The Revolut case, read as more than a single corporate incident, points to an uncomfortable but important reality for the crypto industry under MiCA and DAC8-era compliance requirements. When a verified, documented real identity is linked to a detailed record of someone's cryptocurrency holdings, and that combination reaches unauthorized parties, the resulting risk goes well beyond the usual concerns about code vulnerabilities or exchange hacks. It becomes a personal safety problem. The crypto world is not unfamiliar with that dynamic.

Two lessons emerge. The first concerns KYC data itself: collecting and linking identity records to financial activity is a regulatory necessity, but it creates a concentrated target. The more detailed the profile, the greater the potential damage if that profile reaches the wrong hands, for any reason. The second concerns process: incidents like these, hitting different companies within days of each other, should push every financial operator, traditional or crypto-native, to strengthen not just their technical defenses but the human verification procedures around requests that appear to come from legitimate authorities. Security, as this case makes plain, is as much a matter of people and process as it is of code and cryptography.

Promotional content