Revolut Data Leak Exposes Passports and Bitcoin Records After Phishing Scam

Fintech giant Revolut disclosed sensitive customer records—including passport copies, verification selfies, and full Bitcoin transaction histories—after staff fulfilled an unauthorized data request sent from a fraudulent government email domain, according to disclosures confirmed on September 12, 2026.

The Anatomy of a Social Engineering Breach

Here is the math: corporate technical perimeters are rarely breached through brute-force decryption. Instead, they fall when human actors misinterpret hostile traffic as routine administration. According to reports from Euro Weekly News and blockchain investigator ZachXBT, the incident unfolded when bad actors leveraged an authentic-looking government agency domain that successfully bypassed standard mail verification protocols.

Staff treated the inbound inquiry as a legitimate statutory demand. They subsequently released a comprehensive bundle of customer files before management flagged the mailbox as unauthorized and disconnected the channel. Revolut maintains that its core internal databases were not compromised, no capital left customer balances, and authentication passcodes remained secure. But the damage to data privacy is already finalized.

The Bottom Line

    Exposed Assets: Scans of passports, driving licenses, original verification selfies, and full transaction histories including IBANs and Bitcoin transfer trails.

    Attack Vector: An impostor utilizing a genuine government email domain that passed standard mail filtering checks, duping human staff.

    Downstream Risks: High-net-worth users face elevated exposure to sophisticated phishing, SIM-swapping, and targeted identity fraud.

Decoding the Exposed Ledger and Identity Papers

The scale of the disclosure extends far beyond simple email addresses. Based on internal customer notifications reviewed by investigators, the transmitted dossier contained full legal names, dates of birth, reported occupations, residential addresses, emails, and phone numbers. Crucially, the files included financial statements tracking IBAN numbers, account opening timestamps, withdrawal logs, and granular payment trails.

While Revolut clarified that the exposed biometrics were limited to original user-submitted still photos rather than live facial recognition templates, the collected documents provide everything necessary for synthetic identity creation. A clear passport scan matched with a primary verification selfie allows malicious actors to open secondary banking accounts, apply for unsecured credit, or initiate SIM-swap attacks through telecommunications providers.

Market Implications and the Fintech Compliance Challenge

When human validators process fraudulent administrative requests under the guise of statutory enforcement, institutional trust takes an immediate hit.

Revolut app on phone and Euro cash
Photo: euroweeklynews.com
Data Category Exposure Status Downstream Threat
Identity Documents Confirmed Leaked Synthetic fraud, unauthorized credit applications
Verification Selfies Confirmed Leaked Bypass of weak biometric verification layers
Crypto Transaction Trails Confirmed Leaked Targeted spear-phishing and extortion
Account Passcodes Secure / Unaffected None directly via this vector

Mitigation Strategies for Affected Users

Following disclosures made by cybersecurity authorities and on-chain monitors, affected users must operate under the assumption that their transaction histories and identification documents are actively circulating among secondary markets. Security experts recommend immediate protective registration with credit reference agencies, such as CIFAS in the United Kingdom, and contacting national cybersecurity centers like Spain’s INCIBE.

Furthermore, locking down cellular accounts against unauthorized port-outs is critical to prevent attackers from intercepting two-factor authentication codes. As financial institutions grapple with increasingly convincing social engineering techniques utilizing spoofed institutional domains, the friction between automated compliance and manual verification will only intensify.

Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute financial advice.

Revolut Data Breach: How a Fake Government Email Got Passports, Selfies & Bitcoin Records
Photo of author

Alexandra Hartman Editor-in-Chief

Editor-in-Chief Prize-winning journalist with over 20 years of international news experience. Alexandra leads the editorial team, ensuring every story meets the highest standards of accuracy and journalistic integrity.

Celebrating My 100th Premier League Appearance

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.