Revolut data breach exposes IDs and bitcoin records

Digital banking firm Revolut has confirmed a data breach in which an impersonator using a legitimate government agency email domain tricked the company into handing over sensitive customer information to an unauthorized third party.[1][2][8]

Notifications sent to affected users say the exposed data includes full names, dates of birth, home addresses, email and phone numbers, as well as copies of passports or driver’s licenses used for know-your-customer checks.[2][3][5] In some cases, verification selfies, account statements, IBANs and full transaction histories, including detailed bitcoin and other crypto activity, were also shared.[2][3][9][11] Revolut describes the incident as impacting a “limited number” of customers and says those individuals have been contacted directly.[1][2][8]

Revolut characterizes the incident as a “sophisticated external impersonation attack” in which an unknown actor sent fraudulent information requests from an email account operating under a real government agency domain, complete with valid authentication credentials.[2][4][6] Staff treated the request as genuine, fulfilled it under the assumption of lawful authority and only later determined the mailbox was unauthorized, at which point Revolut blocked the address and alerted the relevant agency, law enforcement and regulators.[1][4][8]

The company stresses that its production systems, customer accounts and funds were not directly compromised, and that no passwords, passcodes, login credentials or biometric templates were exposed in the incident.[1][2][6][8] There is currently no indication that this breach involved exploitation of a software vulnerability, and no public CVE has been tied to the impersonation scam; known Revolut-related issues such as CVE-2026-73353 in the Revolut Gateway for WooCommerce plugin, a medium-severity broken access control flaw with a 5.3 CVSS score, are distinct and unrelated server-side risks.[7][13]

The nature of the exposed data, especially identity documents, selfies and detailed transaction records, raises the risk of downstream identity theft, account takeover attempts at other institutions and highly targeted phishing or extortion campaigns.[2][3][9][11] Bitcoin and broader crypto histories linked to names and addresses could also be valuable to threat actors seeking to profile high-value targets or deanonymise past activity.[3][4][9]

Revolut says it has notified regulators and is working with the impacted government agency to investigate how the fraudulent mailbox was established and why it passed existing checks, while promising to tighten internal verification of official data requests.[1][4][8] Affected customers are being advised by Revolut and consumer advocates to monitor their accounts for suspicious activity, consider replacing exposed identity documents where feasible and remain alert to unsolicited contact that references specific transactions or personal details disclosed in the breach.[2][5][15]

References

  1. Revolut confirms sensitive customer data breach after fake …
  2. Revolut confirms customer data breach through fake …
  3. Bitcoin activity, passports exposed after Revolut falls for …
  4. Revolut Breach: Fake Gov Email Leaked KYC & BTC Data
  5. Revolut fake government email: passports and Bitcoin data
  6. Revolut Confirms Sending Passport and Bitcoin Records to …
  7. Revolut CVEs and Security Vulnerabilities – OpenCVE
  8. Revolut says some customer data was exposed in e-mail-based scam
  9. Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Breach – X
  10. VYPR — Vulnerability Intelligence
  11. CVE-2026-73353 | Tenable®
  12. Revolut data hack: what you need to know – Which? – Which.co.uk

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply