← TradeAssi News
exchangeSeptember 12, 2026·TradeAssi Newsroom

Revolut Data Breach Exposes Customer Passports and Bitcoin Transaction Records

TL;DR

  • Revolut fulfilled a fraudulent government inquiry, leaking user passports and cryptocurrency transaction histories.
  • Reports indicate the social engineering scheme specifically compromised records belonging to high-net-worth customers.
  • The security lapse raises concerns over verification standards and potential regulatory scrutiny for the fintech firm.

Fintech firm Revolut has suffered a notable security breach after complying with an unauthorized information request, leading to the unauthorized disclosure of sensitive user identification and cryptocurrency activity. The incident resulted in the exposure of customer passports alongside detailed Bitcoin transaction histories.

According to a report by BeInCrypto, Revolut confirmed that the compromise was initiated via a phishing attack involving a fraudulent government email. Attackers managed to manipulate the platform's standard inquiry response procedures, ultimately obtaining protected client records.

High-Net-Worth Accounts Impacted

Reports from CryptoSlate and Coinpedia highlight that the incident specifically affected the data of wealthy and high-net-worth clients. CryptoPotato noted that the breach relied on a sophisticated social engineering scheme, which allowed perpetrators to circumvent standard verification protocols by posing as legitimate state authorities.

By successfully impersonating an official agency, the unauthorized party managed to retrieve both identity documents and complete records of past Bitcoin transactions. The exposure of transaction ledgers linked directly to verified passports presents substantial privacy risks, effectively stripping away the pseudonymity typically associated with cryptocurrency holdings.

Scrutiny Over Compliance and Platform Security

The breach underscores ongoing challenges centralized financial platforms face when balancing regulatory compliance with data security. While centralized services routinely archive user identification files to satisfy Know-Your-Customer mandates, storing these records alongside on-chain transaction histories creates high-value targets for attackers.

Industry observers note that the security lapse is likely to invite strict regulatory scrutiny regarding how fintech institutions vet and authenticate formal data requests. Because the breach stemmed from social engineering rather than a direct software exploit, questions remain about internal oversight and the operational controls governing customer data protection. The compromise could also impact consumer confidence in centralized fintech platforms that combine traditional banking features with digital asset management.

#revolut#data breach#bitcoin#fintech#security

This article was reconstructed from public reporting with AI assistance and is for informational purposes only — not financial advice. See our editorial policy.