
Revolut handed over KYC and full bitcoin-linked histories after fake government request
The firm says no customer funds were lost, but it has not disclosed how many users were affected.
Revolut disclosed customer identity documents, residential addresses, and full transaction histories after a fraudulent government-style request passed internal checks. The handover included records “including all bitcoin activity,” creating identity-to-BTC linkage risk even as Revolut said “customer funds remained safe.”
Revolut Hands Over KYC and Full Bitcoin-Linked Histories After Fake Government Request
Revolut handed over customer data after a request that appeared to come from a legitimate government agency cleared the firm’s internal checks. The company later contacted the real agency and determined the request was fraudulent, after the data had already been disclosed.
The exposed material included identity documents and residential addresses alongside transaction histories. Revolut told affected users that “customer funds remained safe,” and said it has since notified affected users and regulators and blocked the source of the request.
The failure mode was not a wallet drain. It was authorization. Once the inbound request was treated as valid, the impersonator received the same compliance package Revolut already held for KYC purposes.
Why “Including All Bitcoin Activity” Changes the Risk Profile for Affected Users
The phrase that matters is “including all bitcoin activity.” A full transaction history paired with KYC turns a fintech database into a linkage layer between real-world identity and onchain behavior.
The files reportedly included passports or driving licences, verification selfies, names, dates of birth, occupations, home addresses, emails, phone numbers, IBANs (International Bank Account Numbers), account statements, withdrawal records, and full transaction histories. That is enough to support identity fraud, but it also supports something more specific to bitcoin holders: targeting.
Bitcoin transactions are public on the blockchain, but passports, addresses, and occupations are not. Intermediaries sit in the middle and can connect the two. If an attacker gets both the identity side and the “all bitcoin activity” side, they can build a map from a person to their bitcoin flows and use it to select victims with larger balances or higher activity.
This is why “no funds lost” is not the end of the story. The immediate damage is informational, and the second-order risk is physical and social: phishing, SIM swaps, extortion attempts, and tailored impersonation that uses accurate personal details.
The incident also fits a broader pattern: AI-assisted impersonation makes convincing emails, documents, and bureaucratic requests cheaper to produce at scale. The security question shifts from how well firms store data to how much sensitive data they collect, retain, and can be compelled or tricked into revealing.
What’s Still Unknown: Scope, Targeting, and the Impersonated Agency
Revolut has not disclosed how many customers were affected. That keeps the scope as an open variable for anyone trying to price counterparty risk across fintech rails.
The impersonated government agency has not been identified in the disclosed details, and the time window between the handover and Revolut’s separate verification with the real agency is also not specified. Those two facts matter because they define how long the attacker had to iterate on requests and whether the same playbook could have been reused.
There is also an unresolved targeting question. Onchain investigator ZachXBT said in a Telegram broadcast that the breach “appeared limited in size and may have targeted high-net-worth users.” That assessment is not confirmed by Revolut, but it is directionally consistent with the value of the dataset: the payoff is higher when the victim set is smaller and richer.
Regulator follow-up is another pending catalyst. Revolut says it notified regulators. Whether that triggers required disclosures, remediation timelines, or process changes will determine if this stays a one-off control failure or becomes a longer compliance overhang.
My Read: This Is a Counterparty-Data Shock, Not a Funds-Loss Event
The threshold that matters is scope. If Revolut later quantifies affected users and the exact fields handed over, the market can treat this as a contained authorization failure. If it stays vague, the risk premium is persistent because nobody can bound the blast radius.
I also care more about the pairing than the individual fields. “Including all bitcoin activity” plus KYC is the dangerous combo, because it converts public onchain data into a named ledger of people and flows. That is what makes this incident matter in practical terms.