What exactly happened?
Revolut, the European fintech company, has confirmed a leak of sensitive data affecting some of its clients. According to the firm, attackers used a legitimate email domain belonging to a government agency to send a fake request for information. Revolut assessed the request as genuine and released the data.
The incident was first flagged by an on-chain investigator operating under the name ZachXBT. Revolut subsequently confirmed his findings. So much for the facts that appear consistently across sources (Incrypted, The Block, Decrypt, CryptoSlate).
What data may have leaked?
According to the information received by the affected clients (and cited by CryptoSlate and Decrypt), the list of released data may have included:
| Category | Specific data |
|---|---|
| Identity documents | copies of a passport or driver's license, verification selfie |
| Personal data | name, date of birth, occupation, home address, phone number |
| Banking data | IBAN, account statements |
| Transaction history | records of withdrawals and complete transaction history including bitcoin activity |
A verification selfie is a photograph of the face taken during identity verification (KYC, meaning "know your customer"), which banks use to confirm that the person registering is the actual owner of the document.
According to sources, Revolut describes the scope as a "limited number" of clients. The exact figure is not publicly known.
How did the attack work?
The core of it was not a classic hack of Revolut's systems. According to CryptoSlate, the request came from an unauthorized mailbox, which nevertheless ran within the domain infrastructure of a government agency. In other words, the sender's address looked genuine because it actually belonged to the agency's domain.
That makes the incident more of a failure in the process of verifying legitimate requests from public authorities than a breach of a database. It is the type of attack referred to in English as a "fraudulent data request," that is, a fraudulent request for data that abuses the trust between institutions.
Who was the target?
According to The Block, ZachXBT speculated that the attack may have targeted wealthy users (high-net-worth). CryptoSlate's headline refers to "wealthy customers." However, this is so far a hypothesis from the investigator, not a confirmed fact from Revolut. We therefore label it as unconfirmed.
Why does this matter for crypto?
The money itself did not leak. The problem is the combination of the data. When someone holds an identity document, a home address, a phone number, and a complete bitcoin transaction history all at once, they gain the material for targeted phishing, extortion, or so-called "wrench attacks" (physical threats against people known to hold crypto).
Transaction history also makes it possible to link a real identity to specific on-chain addresses. This is exactly the kind of deanonymization that experts have long warned about in connection with KYC data leaks.
What remains unknown?
Publicly, we still do not know the exact number of affected clients, which specific government agency and jurisdiction was involved, or whether and how the leaked data was further abused. We also do not know what remedial measures Revolut has put in place. These points are not documented in the available sources.
What to watch out for with this type of incident
This is not advice on what to do with your money, but rather a set of general patterns worth watching in KYC data leaks: an elevated risk of targeted phishing against affected users, possible account takeover attempts, and the company's official communication about the scope and remediation. It is also worth watching whether the regulator in the given jurisdiction begins investigating the incident.

