Revolut disclosed Saturday that a fake government email request slipped past its internal security controls late Friday, prompting the digital bank to hand over a trove of customer identity documents including passports, driver's licences, verification selfies, residential addresses and full transaction histories covering bitcoin activity. The request carried credentials that passed Revolut's checks, and the bank only discovered the fraud after separately contacting the agency that supposedly sent it. No customer funds were lost, but the bank has not disclosed how many users were affected, and onchain investigator ZachXBT suggested the breach may have targeted high-net-worth customers.
Why it matters
The exposure lists exactly the fields KYC programs are designed to collect, and the breach reframes that compliance data as the attack surface. AI-assisted impersonation is making convincing government emails, documents and bureaucratic requests cheap to produce at scale, while financial companies continue to hold increasingly detailed records about who their customers are, where they live and how they move money. Once that record is exfiltrated, it cannot be recalled, and it cannot be replaced.
Market impact
Bitcoin makes the linkage especially dangerous. Blockchain transactions are public, but identity sits outside the network until an intermediary connects the two. A leaked KYC file effectively maps a real person to their onchain activity, giving attackers a ready-made target list for phishing, social engineering or extortion. The incident also gives zero-knowledge proof systems a more concrete use case. Institutions could verify that a customer satisfies a requirement without ever holding the underlying passport, address or transaction data that just walked out of Revolut.
Frequently asked questions
-
How did a fake government email get past Revolut's security checks?
The fraudulent request carried credentials that looked legitimate and passed the bank's internal checks, so Revolut handed over customer data before separately contacting the agency and discovering the request was fake.
-
What customer data was exposed in the Revolut breach?
Exposed fields included passports or driver's licences, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs, account statements and full transaction histories including bitcoin activity.
-
Were customer funds affected by the Revolut breach?
No. Revolut said customer funds remained safe, though the bank has not disclosed how many users had their identity and transaction data exposed.
-
Why is bitcoin transaction history especially sensitive in this breach?
Blockchain transactions are public, but identity sits outside the network until an intermediary connects the two. A leaked KYC file effectively maps a real person to their onchain activity.
-
How do zero-knowledge proofs reduce this kind of KYC breach risk?
ZK systems let an institution confirm that a customer satisfies a requirement without ever holding the underlying passport, address or transaction data, shrinking the attack surface that just walked out of Revolut.
CoinDesk