Revolut Admits KYC and Bitcoin Data Exposed in Government Impersonation Scam
Fintech giant Revolut has disclosed a significant data breach after an unauthorized third party successfully impersonated a government agency to obtain sensitive customer information. The data exposed includes Know Your Customer (KYC) details, account information, and full transaction histories, including Bitcoin transactions.
Revolut described the event as a “sophisticated external impersonation scam” and began notifying a “limited number” of affected customers on Friday. The attackers reportedly used a compromised email account from a legitimate, albeit unnamed, government domain to submit fraudulent data requests, which the company then fulfilled.
What data was compromised in the Revolut breach?
The scope of the exposed information is extensive, painting a detailed picture of the affected customers’ financial lives. According to notifications sent by the company, the breach includes a wide array of personal and financial data. Former Mt. Gox CEO Mark Karpelès, who confirmed he was among those affected, shared a copy of the notice he received.
Exposed personal details include customers’ full names, dates of birth, postal addresses, email addresses, and telephone numbers. Crucially, identity documents submitted for verification purposes, such as passports and driver’s licenses, were also compromised. Verification selfies, used to match a user to their ID, may have been disclosed as well.
On the financial side, the leak exposed account statements, International Bank Account Numbers (IBANs), and complete transaction and withdrawal records. For cryptocurrency users, this includes their full Bitcoin transaction histories, providing a clear window into their digital asset activities on the platform. The company has maintained that customer funds and its core systems were not directly affected.
Despite these details, Revolut has declined to specify how many customers were impacted or in which markets. The firm also refused to identify the government agency whose email domain was exploited in the attack, leaving key questions about the incident’s origin unanswered.
A sophisticated scam targeting high-value users
The attack vector represents a worrying trend in cybersecurity: the exploitation of trust in official channels rather than a brute-force technical hack. By using a legitimate government email domain, the perpetrators bypassed initial suspicion, making their request for information appear authentic. This social engineering tactic highlights a critical vulnerability in the processes companies use to interact with law enforcement and regulatory bodies.
In response, Revolut stated it quickly identified the malicious activity, blocked the fraudulent email address, and reported the incident to the relevant government agency. The company has also alerted law enforcement, financial regulators, and data protection authorities. This incident underscores the persistent threat posed by sophisticated crypto scam networks that continuously evolve their methods.
Onchain investigator ZachXBT, a prominent figure in the crypto community, speculated that the attack was not random. He suggested the breach was likely a targeted effort aimed at high-net-worth individuals. “While the incident is likely limited in size it seems to have been targeted at high net worth users,” he wrote, raising concerns that the stolen data could be used for highly personalized follow-up attacks.
This type of detailed financial and personal information is a goldmine for criminals. It can be used to execute spear-phishing campaigns, SIM-swapping attacks to take over mobile phone numbers, or even extortion attempts against individuals known to hold significant crypto assets. The inclusion of Bitcoin transaction data makes the threat particularly acute for crypto investors.
Fintech and crypto firms face a wave of data exposures
The Revolut incident is not an isolated event but the latest in a string of security failures across the financial technology and cryptocurrency sectors. These breaches often stem from vulnerabilities in third-party systems or through social engineering, demonstrating that a company’s security is only as strong as its weakest link.
Just last month, crypto wallet provider SafePal disclosed that a flaw in an external order-tracking system had exposed the personal information of nearly 40,000 customers. The leaked data included names, contact details, and shipping addresses, though the company confirmed user funds and private keys remained secure. This type of event can shake investor confidence in the platforms they use daily.
Similarly, hardware wallet manufacturer Trezor has been grappling with breaches originating from its partners. The company recently revealed that an incident at its shipping provider, ShipMonk, affected approximately 67,000 US customers, exposing their names, addresses, and contact information. This followed a separate disclosure where a compromised third-party email service was used to send phishing emails from Trezor’s official domain.
These events highlight a recurring pattern: attackers are increasingly targeting the supply chain and official communication channels surrounding crypto companies. By compromising a trusted vendor or impersonating a legitimate authority, they can bypass robust internal security measures. This poses a systemic risk to an industry that handles vast amounts of sensitive user data for KYC and Anti-Money Laundering (AML) compliance.
Bad timing for Revolut’s global expansion plans
This data breach comes at a particularly sensitive time for Revolut as it pushes forward with ambitious plans to expand its banking and crypto operations, especially in the United States. The British-based firm, which serves over 80 million customers globally, is actively seeking to establish itself as a major player in the US financial market.
Earlier this month, Revolut secured conditional approval from the U.S. Office of the Comptroller of the Currency (OCC), a critical step toward its goal of launching a national bank in the country. The proposed bank plans to offer traditional banking products alongside stablecoin services. A security incident involving customer data could attract intense scrutiny from US regulators who are already cautious about the crypto industry.
The company has also been focused on growing its crypto offerings. It recently began rolling out EURR, its first euro-backed stablecoin, in several European markets. Furthermore, it has been enhancing its standalone crypto exchange, Revolut X, by integrating AI assistants like Claude and Gemini to help users analyze markets and execute trades.
This highlights the contrast between the growing institutional faith in crypto and the persistent operational risks.
A failure to protect customer data, especially through a process-related vulnerability, could damage Revolut’s reputation and create headwinds in its discussions with regulatory bodies. For a company seeking a banking charter, demonstrating ironclad security and compliance protocols is paramount. This breach raises questions about the robustness of those protocols when faced with sophisticated social engineering.
What this means for crypto investors and security
The targeting of specific financial information like Bitcoin transaction history signals a clear and present danger to crypto holders. This data allows criminals to profile potential victims, estimate their holdings, and craft highly convincing and personalized scams. Affected Revolut users must now be on high alert for phishing emails, suspicious text messages, and any unusual activity related to their accounts.
The incident also serves as a stark reminder of the “KYC problem” in cryptocurrency. While necessary for regulatory compliance, the centralization of vast amounts of personal data creates high-value targets for hackers. The promise of decentralization is often at odds with the reality of using centralized exchanges and fintech apps that are required to collect and store this information.
For Revolut, the path forward involves not only shoring up its data request verification processes but also being transparent with its customers and regulators. The firm’s reluctance to disclose the number of affected users or the compromised government agency may fuel further distrust. How it manages the fallout and communicates its remedial actions will be critical in rebuilding confidence.
Ultimately, this breach underscores an industry-wide challenge. As attackers shift from purely technical exploits to sophisticated impersonation and social engineering tactics, companies must evolve their defenses. This includes more rigorous, multi-layered verification for any external request for sensitive data, regardless of how official the source may appear. For investors, it reinforces the timeless crypto mantra: be vigilant.

