Revolut exposed KYC and Bitcoin transaction data in fake-request scam
Revolut exposed customer KYC and Bitcoin transaction data after falling victim to a sophisticated impersonation scam using a legitimate government email domain.
Revolut handed over customer records to someone who wasn’t entitled to them. The entry point: a fraudulent data request sent from an email account on a legitimate government agency domain. The company’s own characterization, per The Block’s report on Revolut’s disclosure, was a “sophisticated external impersonation scam.” Sophisticated or not, the records went out.
The list of what was exposed is long. Names, dates of birth, occupations, postal and email addresses, phone numbers, passport and driver’s license copies, verification selfies, account statements, full transaction histories. Bitcoin transaction records too, according to Cointelegraph’s account of the data leak. Revolut said a limited number of customers were affected and that its systems and funds remain unaffected.
The attackers have since started publishing what they took. Their stated terms: “We’re going to start releasing more and more data everyday until revolut pays for leaking their customers.” Daily releases until payment. No payment disclosed.
Two individuals named in the reporting as having had identity documents and selfies published are tennis player Alexander Shevchenko and Felix Römer, CEO of Gamdom. That’s a data point about targeting, not a customer count — Revolut hasn’t offered one.
Onchain investigator ZachXBT wrote that “while the incident is likely limited in size it seems to have been targeted at high net worth users.” That detail matters more than the headline number. When attackers hold KYC documents, contact details, account statements, and Bitcoin activity together, the combination maps both identity and financial behavior — even when no funds actually moved.
It was a fraudulent information request that cleared because it arrived on authentic-looking government infrastructure.
CoinGecko lists Bitcoin at $77,687. Nothing in the available facts connects the incident to the Bitcoin network or to any movement of customer funds.
The attackers reportedly began publishing data on September 12. The specific government agency domain, the total number of affected customers, the attackers’ identities, and whether the exposure was confined to one market remain unknown.