Financial technology firm Revolut has confirmed a security breach that resulted in the disclosure of sensitive customer data, including passport copies and full Bitcoin transaction histories, after the company responded to a fraudulent request masked as a legitimate government inquiry.
Impersonation leads to major data leak
A spokesperson for Revolut stated that the breach occurred following a “sophisticated external impersonation scam.” This attack involved a malicious actor submitting a request via an email sent from an official government agency domain, which successfully passed the company’s verification checks.
Revolut reported that only a limited number of customers were affected. The company said it had blocked the compromised email address, notified the relevant government agency, as well as law enforcement and regulators, and took measures to secure its systems. According to Revolut, no customer funds or internal systems were impacted by this incident.
Revolut described the incident as a highly sophisticated impersonation scheme using a real government agency domain, emphasizing that its internal systems and customer funds remain secure.
Despite confirming the breach, Revolut did not disclose the exact number of customers affected or reveal the identity of the impersonated agency. The attack has prompted concerns from both customers and crypto security analysts regarding the potential risks of compliance-based identification processes in the sector.
Data exposure includes Bitcoin account history
The compromised information was extensive. Affected customers’ notification letters, shared by crypto investigator ZachXBT, revealed that details ranging from full names, birth dates, and occupations to contact details such as addresses, emails, and phone numbers were exposed. Documentation included passport or driver’s license copies and customer verification selfies.
Financial data released as part of the breach included account statements with IBAN and wallet reference numbers, records of withdrawals, and detailed transaction histories, notably Bitcoin activity. However, Revolut stated that biometric facial telemetry was not part of the exposed data.
The leaked financial details covered users’ crypto wallets, full Bitcoin transactions, and supporting documents, raising serious safety worries for those involved.
ZachXBT, a prominent investigator in the crypto space, claimed the breach appeared to target high-net-worth users. He noted that the incident increased concerns about “wrench attacks,” which are physically coercive assaults designed to force individuals to surrender assets. The wider community criticized current know-your-customer (KYC) practices, with some arguing that such regulations add risk without delivering real security benefits for customers.
Mini dictionary: Wrench attack, a type of physical assault in which criminals use threats or violence to force an individual to provide access to their cryptocurrency or digital assets, often after learning their identity and holdings from leaked data.
Sector faces increasing pressure over security
The breach at Revolut comes amid heightened scrutiny of data security within the crypto industry. Hardware wallet provider Trezor, which specializes in secure storage for digital assets, recently expanded the scope of a support-vendor breach that compromised tens of thousands of customer records. Social media platform X also reported an incident resulting in a wave of unexpected password resets for users.
| Company | Incident | Type of Data Exposed |
|---|---|---|
| Revolut | Email impersonation breach | Personal ID, verification selfies, Bitcoin transaction data |
| Trezor | Support-vendor breach | Customer contact details |
| X | Password reset breach | User account security threatened |
Revolut, originally launched as an online banking app and now offering a broad suite of financial services, including cryptocurrencies and a recently introduced EURR stablecoin, is currently considering an initial public offering.
The company assured the public that the fallout remains contained but did not provide a timeline for the conclusion of its investigation into the event.




