Security Hub

Revolut Exposed Customer KYC Files After a Spoofed Government Request

Published: Sep 12, 2026By Aleksandar Dukic

Key Analysis

Revolut handed over customer ID documents, selfies, and Bitcoin transaction histories after a social-engineered request posing as a government agency.

Revolut Exposed Customer KYC Files After a Spoofed Government Request

Listen To This Article

Revolut Exposed Customer KYC Files After a Spoofed Government Request

5m 12s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Revolut disclosed sensitive customer data, including identity documents, selfies, and Bitcoin transaction histories, after complying with a request that was later found to be a spoofed government demand, according to a CoinDesk alert posted September 12, 2026. The data left the building not through a hacked server but through the front door, released by staff who believed they were answering a legitimate law-enforcement order.

That distinction matters. This was not a technical breach in the usual sense. No malware, no leaked credentials, no unpatched endpoint. The attacker forged the authority of a government agency and Revolut's process for validating that authority failed. The information handed over was exactly the kind a regulated fintech is obligated to collect and keep: passport or ID scans, biometric selfies used for liveness checks, and a record of on-chain activity tied to a named individual.

The attack targeted trust, not code

Compliance data is a honeypot. To operate legally, platforms like Revolut collect and store the most identity-revealing documents a person owns, then link them to financial behavior. A minimal-verification card exists precisely because some users want to avoid handing that dossier to any single company. This incident shows why. The value of a KYC archive to an attacker is not that it is hard to steal, but that once stolen it cannot be changed. You can reset a password. You cannot reset your face or your passport photo.

Spoofed law-enforcement requests are a known and growing method. An attacker impersonates a police force, tax authority, or regulator, sends a request that looks procedurally correct, and relies on the recipient's fear of obstructing a real investigation. Firms process large volumes of these demands, and the pressure to respond quickly works against careful verification. When the checks are manual and the request looks routine, a well-crafted forgery gets through.

Bitcoin histories are the sharpest part of the leak

The exposure of Bitcoin transaction histories deserves separate attention. On its own, a blockchain address is pseudonymous. Paired with a verified identity, ID document, and selfie, it stops being pseudonymous for that person entirely. An attacker who now holds this package can map a named individual to their on-chain balances, counterparties, and spending patterns. That combination raises the risk of targeted extortion, phishing, and physical threats against holders known to control meaningful funds.

This is a recurring failure mode across custodial platforms. When you spend or transact through a service that holds your identity, you are trusting that service to keep the identity-to-activity link private. Custodial convenience concentrates that risk in one place. Spending from your own wallet through self-custody options does not eliminate identity checks at the card issuer, but it changes who holds the keys and narrows how much a single leak can reveal about your full balance.

The pattern is bigger than one firm

Recent months have shown the same theme repeating. When Trezor warned users of phishing after its email provider was breached, the weak point was a third party, not the hardware. The Bank for International Settlements has warned that AI is compressing the exploitation window from weeks to minutes, which makes convincing forgeries cheaper and faster to produce at scale. And when a Coldcard attacker drained funds across hundreds of vaults, the entry point was user-side social engineering rather than a break in the device itself.

The common thread is that the human verification layer, not the cryptography, keeps failing. Revolut, headquartered in the United Kingdom and serving tens of millions of accounts across Europe, sits under some of the strictest data-protection rules in the world. Compliance obligations did not prevent this. If anything, the obligation to collect the data is what created the target.

Practical exposure for affected users

For anyone who has completed identity verification with a platform holding crypto activity, the useful response is defensive, not reactive. Assume that ID documents and selfies, once collected, may eventually leak somewhere and cannot be revoked. Treat any inbound message referencing your real transaction history or ID details as a likely phishing attempt built on stolen data, since attackers use leaked context to sound legitimate. Where a service offers hardware-key or passkey login rather than SMS, use it, because knowledge of your identity does not help an attacker who still needs a physical key.

There is no confirmed count of affected accounts in the initial alert, and Revolut has not published a full breakdown of scope at the time of writing. That gap matters. Until a firm states how many records left and which fields were included, users cannot size their own exposure, and the safe assumption is the broader one.

Overview

Revolut released customer KYC documents, selfies, and Bitcoin transaction histories after complying with a spoofed government request, per a CoinDesk alert on September 12, 2026. The failure was in verifying the requester's authority, not in the platform's code. The leaked combination of verified identity plus on-chain history is the most damaging kind, because it de-anonymizes named holders and cannot be reset. The incident fits a wider pattern in which the human verification layer, rather than the cryptography, is the point of failure. Affected users should treat ID data as permanently exposed and stay alert to phishing built on that context.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.