Revolut confirms data breach after fraudulent government data request
Key Takeaways
- •The fraudulent request obtained potentially sensitive identity, contact, account, and transaction information from a limited number of directly notified customers.
- •Revolut said the breach did not compromise its systems or customer funds and has blocked the fraudulent email address.
- •The attacker’s identity, the impersonated authority, the number of affected accounts, and the method used to access or spoof the government email remain unknown.
- •Combining identity documents, residential information, and Bitcoin activity could increase risks including account takeover and physical coercion of crypto holders.
- •The breach is subject to regulatory scrutiny in Europe while Revolut expands its banking and crypto operations.

Revolut has confirmed a data breach in which an unknown third party submitted a fraudulent request for customer information. The attacker used an email account on a legitimate government domain to obtain copies of identity documents and complete Bitcoin transaction histories.
Revolut, a British digital bank, combines current accounts, payments, securities trading and crypto services in one application. Its crypto business also includes the standalone trading platform Revolut X and the euro stablecoin EURR. The company said it served 80 million customers worldwide in August 2026.
The breach comes as Revolut is expanding its regulated banking and crypto operations. In early September 2026, the US banking regulator, the Office of the Comptroller of the Currency (OCC), granted the company conditional approval for a national bank charter. In August, Revolut began launching its EURR stablecoin in Denmark, Poland and Portugal.
Affected customers received notification emails in September 2026. Revolut has not disclosed how many accounts were involved or which authority the attacker impersonated.
How the fraudulent request deceived Revolut
Security researchers have documented fraudulent requests for user data made under emergency provisions since 2021. The pattern is known in the industry as a Fraudulent Emergency Data Request. Criminals typically take control of, or spoof, an email account associated with a genuine police or government domain. They then use the account to request user data while claiming that an emergency requires an immediate response.
The emergency exception bypasses the ordinary review process, which generally involves a court order. Companies may therefore respond within 30 to 60 minutes. That speed makes the process attractive to attackers. Apple, Meta, Discord and Verizon have previously fallen victim to the scheme, initially involving the groups Lapsus$ and the Recursion Team. In 2024, the FBI issued an official warning about the pattern.
In Revolut's case, the attacker used an account on a legitimate government domain. A company spokesperson described the incident to TechCrunch as a sophisticated external impersonation scam. The digital bank subsequently blocked the fraudulent address. According to Revolut, the incident affected neither its systems nor customer funds. The company had not published a separate statement on the matter at the time of the report. TechCrunch reported on the incident here:
“Revolut recently identified a sophisticated external impersonation scam in which an unauthorized third party used a legitimate government domain email to make fraudulent requests for information.” — Revolut spokesperson to TechCrunch
Revolut said it notified the affected authority, law enforcement agencies, data protection regulators and financial supervisors. However, it has not identified the authority that the attackers impersonated. It is also unclear whether the attacker compromised the government email account or technically spoofed the domain. Previous cases have involved both methods.
The method presents a particular challenge for financial institutions, which routinely respond to official information requests. Verifying an urgent request through a second communication channel can take longer than the emergency process is designed to allow.
What information may have been exposed
The customer notification lists a broad range of potentially exposed information. It includes names, dates of birth, postal and email addresses, and phone numbers. The notification also refers to copies of identity documents, including passports and driver's licenses, as well as verification selfies collected during the Know Your Customer (KYC) process, account statements and complete transaction histories.
The information therefore covers much of the onboarding and account history held by a regulated bank. Revolut has nevertheless described the number of directly notified customers as limited. The company said customer funds were not affected.
Mark Karpelès, the former CEO of crypto exchange Mt. Gox, published a copy of the notification and said that he was among the affected customers. His version additionally listed IBANs, withdrawal logs and complete transaction histories, including Bitcoin transactions. This could expose links between individual customers' bank accounts and their Bitcoin activity.
The on-chain investigator ZachXBT assessed the scope as limited but suspected that the attackers may have selected comparatively wealthy users. It also remains unclear whether the incident affected more than one market.
Under Articles 33 and 34 of the General Data Protection Regulation (GDPR), an incident involving identity documents, biometric selfies and complete financial histories can constitute a high-risk breach requiring notification to affected individuals. Lithuania's State Data Protection Inspectorate (VDAI) has jurisdiction because Revolut holds its European banking license through Revolut Bank UAB. That entity also falls under the supervision of the Bank of Lithuania and the European Central Bank (ECB). Statements from the spokesperson do not establish when Revolut first notified the supervisory authorities.
Combined KYC and Bitcoin data create security risks
A data set containing an identity document, a home address and visible Bitcoin holdings presents more than a privacy concern. It can function as a target list. In the crypto industry, combinations of this kind are regarded as enablers of so-called wrench attacks, in which criminals use physical coercion to force victims to surrender access to their crypto assets.
Someone who knows how much Bitcoin a person holds and where that person lives may not need to launch a technical attack. Copies of identity documents and selfies can also make it easier to take over other accounts. A bank can replace a stolen card number, but an exposed identity cannot be replaced.
The number of reported cases has increased sharply. A CertiK report counted 52 verified wrench attacks during the first half of 2026, involving approximately USD 124.1 million in losses. During the same period a year earlier, the report recorded 39 incidents, an increase of 33% in the number of cases. The earlier losses totaled slightly more than USD 10 million. The increase in financial damage was therefore substantially larger than the increase in the number of incidents. Identity documents and home addresses can also remain useful to criminals for years.
Revolut joins a series of crypto data breaches
The Revolut incident follows several other data breaches involving crypto companies. In August 2026, a leak at wallet provider SafePal affected approximately 39,798 customers, although private keys and balances were not exposed. At Trezor, information belonging to about 67,000 US customers leaked through shipping service provider ShipMonk. A separate breach at the hardware wallet maker's email service provider also enabled phishing messages sent through the legitimate Trezor domain. In both cases, the attack surface was located at a service provider used by the manufacturer.
The largest recent precedent involved Coinbase in May 2025. Bribed support staff abroad provided information on approximately 70,000 customers. The data included names, addresses, images of identity documents, transaction histories and account balances. The extortionists demanded USD 20 million, but Coinbase did not pay. The company's estimated remediation costs eventually reached between USD 180 million and USD 400 million, meaning that the subsequent costs were many times higher than the demand. A smaller insider incident involving about 30 affected customers followed at Coinbase in early 2026.
In these incidents, attackers targeted access to customer databases rather than direct custody of crypto assets. Crypto-related providers collect particularly comprehensive identity information for regulatory purposes. Self-custody therefore offers only partial protection against this type of exposure because much of the identifying information is collected during registration.
For Revolut, the timing adds regulatory scrutiny. The company's conditional OCC approval and the EURR launch come as the review of the data breach is only beginning. The outstanding factual questions include how many accounts were accessed, whether the incident crossed more than one market, how the fraudulent government identity was obtained or imitated, and what the relevant authorities conclude about Revolut's response and notification process.