Skip to content

Revolut Data Leak: Passports, Bitcoin Records Sent to Fraudster

Revolut Data Leak: Passports, Bitcoin Records Sent to Fraudster

Short answer: On September 12, 2026, Revolut confirmed that it had handed passport copies, verification selfies and full bitcoin transaction histories of a limited number of customers to a fraudster who impersonated a government agency from that agency's real email domain. No funds or systems were compromised, but the Revolut data leak links real identities and home addresses to bitcoin activity, which raises the risk of targeted phishing and physical "wrench attacks".

What happened

Revolut, the London-based digital bank and one of Europe's largest fintech apps, received what looked like an official request for customer records. The email came from a legitimate government domain and passed the standard authentication checks for email (SPF, DKIM and DMARC), so the company treated it as genuine and sent the files. It later established that the request was fraudulent.

The incident became public on Saturday, September 12, after on-chain investigator ZachXBT flagged it to his Telegram channel. Revolut then confirmed it to the press, calling it a sophisticated external impersonation scam. The company has not named the agency or the country involved and has not said how many people were affected beyond describing the number as limited.

According to the reports, the records sent for each affected customer included:

  • copies of passports or driving licences and the selfies used for identity verification;
  • full name, date of birth, occupation, home address, email and phone number;
  • account statements with IBANs, withdrawal records and complete transaction histories, including all bitcoin activity and wallet references.

Revolut said it blocked the sender, alerted the impersonated agency, law enforcement, data protection authorities and financial regulators, and contacted affected customers directly. ZachXBT said the leak appeared to target high-net-worth users. By September 14, further reports said the people behind it were demanding payment and threatening to release more material.

How a fake government data request gets through

Banks and exchanges receive lawful requests from police and tax authorities every day and are legally required to respond. That creates an attack surface that has nothing to do with hacking servers. If a criminal gains access to a real government mailbox, or to a domain that the company trusts, the message looks authentic in every technical check.

The weak point is process, not software. A request that arrives from a genuine domain still needs to be verified out of band, for example by calling the agency on a known number or requiring a formal legal instrument through an official portal. Fake "emergency data requests" have hit large tech platforms for years; this case shows the technique reaching crypto-friendly financial apps.

Why a bitcoin transaction history is so sensitive

A bitcoin address on its own is pseudonymous. A withdrawal record that ties that address to a passport and a home address removes the pseudonymity, not just for one transaction but for everything that address and its linked wallets have done before and after.

Leaked itemWhat an attacker can do with it
Withdrawal records and wallet referencesFollow the coins on-chain and estimate current holdings
Home address and phone numberTarget the person physically or by phone
Passport copy and selfieAttempt identity fraud or account takeovers elsewhere
Account statements and IBANCraft convincing phishing that quotes real transactions

A wrench attack is a physical assault or kidnapping aimed at forcing someone to hand over crypto. Such attacks have grown as leaked customer data has spread: France saw a series of kidnappings of crypto holders and their relatives in 2025, and several data leaks at crypto firms this year have fuelled similar concerns.

What it means for you

If you are a Revolut customer and received a notice, assume your identity and bitcoin history are in criminal hands and act accordingly. If you have not been contacted, the direct risk is lower, but the wider lesson applies to anyone who buys crypto through a service that stores identity documents.

  • Expect targeted phishing. Anyone who quotes your real transactions or IBAN is not proven genuine. Revolut and legitimate agencies will not ask you to move funds or share a seed phrase.
  • Move coins to fresh addresses you control. Funds sitting in addresses that appear in the leaked records are easy to monitor; sending them to a new wallet breaks the obvious link.
  • Reduce what you hand over. Every stored passport scan is a future leak. For simple swaps, services that work without an account and without storing documents, as described in our guide to exchanging crypto without registration, keep less of your data in one place.

More practical steps are in our crypto wallet security guide, including why amounts and addresses should stay off social media.

Key takeaways

  • Revolut sent customer records to a fake government request made from a genuine agency email domain.
  • The files included passports, selfies, addresses, IBANs and full bitcoin transaction histories.
  • Revolut says a limited number of customers were affected and that funds and systems were untouched.
  • ZachXBT said the leak appeared aimed at high-net-worth users, raising wrench-attack concerns.
  • Linking identity to on-chain activity is permanent; affected users should move coins to new addresses and expect phishing.

Our overview of how to avoid crypto scams covers the impersonation tricks that usually follow a data leak.

Sources: CoinDesk, Decrypt, BleepingComputer, Help Net Security

Frequently asked questions

Was my money stolen in the Revolut data leak?

Revolut says customer funds and its systems were not affected. The incident exposed personal data and transaction histories of a limited number of customers, who were contacted directly.

What data did Revolut leak to the fake government request?

Reports say the files included passport or driving licence copies, verification selfies, home addresses, contact details, IBANs, account statements, withdrawal records and full bitcoin transaction histories.

What is a wrench attack in crypto?

A wrench attack is a physical threat, assault or kidnapping used to force a person to transfer their cryptocurrency. Leaks that link names and home addresses to crypto holdings make such attacks easier to plan.

← Blog

Read next