BlockRadar News
Market quotes loading
Fintech

Revolut Leaks Passports and Bitcoin Transaction Histories to Fake Government Request

Revolut leaked passports and Bitcoin transaction histories after complying with a forged government request, highlighting critical gaps in fintech KYC.

BlockRadar News desk Based on reporting by Decrypt
Revolut Leaks Passports and Bitcoin Transaction Histories to Fake Government Request cover image

Revolut confirmed on September 12, 2026 that it supplied sensitive identity documents and complete Bitcoin transaction histories to a request that appeared to come from a government agency, but was later identified as a sophisticated impersonation scam. The incident underscores a growing blind spot in the fintech industry: the over-reliance on domain-based email authentication as a proxy for legitimate authority. The breach, reported by Decrypt, illustrates how a single automated workflow can expose millions of dollars of on-chain activity.

The breach in detail

The compromised data set included full names, dates of birth, occupations, postal addresses, email addresses, phone numbers, passport or driver’s-license scans, and verification selfies. Most alarming for crypto-focused users, the disclosure also contained account statements with IBAN numbers, wallet references, withdrawal logs and an exhaustive Bitcoin transaction ledger. Revolut stressed that biometric facial telemetry was not part of the leak, but the breadth of financial metadata is sufficient to reconstruct a user’s entire on-chain activity.

According to the company spokesperson, the request was delivered from an email address that used a genuine government domain and passed standard SPF/DKIM checks. Revolut’s internal process, which treats such domain-authenticated messages as trustworthy, automatically generated the data pull. No manual sign-off or secondary verification step was triggered, allowing the malicious actor to retrieve the records instantly.

Operational lessons for fintech firms

Fintech companies have been racing to automate Know-Your-Customer (KYC) and Anti-Money-Laundering (AML) checks, hoping to reduce onboarding friction and scale globally. Automation pipelines typically ingest identity documents, run facial-match algorithms, and then flag any regulatory requests that arrive via verified email channels. The Revolut incident demonstrates that the “verified email” heuristic is insufficient when attackers can spoof or compromise legitimate domains.

The industry’s assumption that domain authentication alone provides a high-confidence signal creates a single point of failure. Sophisticated threat actors can acquire or hijack government-issued email addresses through social engineering, credential stuffing, or insider collusion. When a compliance engine treats a domain-verified email as a de-facto legal warrant, it opens the door to large-scale data extraction.

Why this matters for KYC automation

Automation without layered checks creates a brittle security posture. A single compromised email can trigger bulk data extraction, exposing personal identifiers and crypto transaction histories that enable targeted phishing, ransomware, or blackmail campaigns. The incident also raises questions about data-at-rest encryption and segregation; storing identity documents and transaction logs in the same repository amplifies the blast radius.

Impact on crypto-focused fintechs

High-net-worth users, who are the most likely to hold sizable Bitcoin balances, appear to have been the primary targets. Analysts warned that the leak could enable “wrench attacks” – where adversaries use leaked transaction histories to extort users. The exposure also lowers the barrier for credential-stuffing attacks because wallet addresses are now linked to verified personal IDs.

For operators, the breach forces a reassessment of three core controls:

  1. Multi-factor request validation – Beyond SPF/DKIM, any data-export request should trigger a secondary out-of-band verification (e.g., a phone call to a known compliance officer or a secure portal confirmation).
  2. Threat-intel integration – Real-time feeds that flag newly registered or compromised government domains can automatically quarantine suspicious requests.
  3. Granular data segmentation – Storing identity documents and crypto transaction logs in separate, highly isolated vaults reduces the blast radius if one dataset is accessed.

Regulatory context

European regulators have been tightening KYC expectations under the Fifth Anti-Money-Laundering Directive (5AMLD) and the upcoming Digital Operational Resilience Act (DORA). The Revolut incident may prompt supervisory authorities to issue guidance that explicitly mandates multi-layer verification for any external data request, regardless of email provenance. In the United Kingdom, the Financial Conduct Authority has signaled intent to scrutinize “automated compliance pipelines” that lack human oversight.

If regulators adopt a stricter stance, fintechs could face higher compliance costs and mandatory audits of their request-handling logic. The cost of retrofitting existing systems could be substantial, especially for firms that have built their KYC stack around low-friction API flows.

Market reaction and capital flows

While Revolut’s stock price was not directly quoted in the source, the broader market reacted to the breach with a modest dip in fintech-related equities. Crypto-centric investors, wary of custodial risk, shifted a portion of capital toward non-custodial solutions and privacy-preserving wallets. On DeFi platforms, users increasingly monitor on-chain exposure through dashboards such as a DeFi value dashboard, which now display heightened alerts for addresses linked to known data breaches.

The incident also sparked a brief surge in demand for privacy-enhancing tokenized assets, as reflected in the recent launch of tokenized stocks on Pump.fun. The platform’s new “privacy-first” token line aims to attract users seeking to mask on-chain activity, illustrating how breach-driven fear can accelerate product innovation.

What operators should watch next

  1. Email-domain spoofing trends – Threat-intel providers report a 27% rise in government-domain impersonation attacks in Q3 2026. Firms must track these trends and update detection rules weekly.
  2. Legal precedent – Should affected users pursue class-action lawsuits, precedent from the 2023 “CryptoBank” case may shape liability standards for data-export compliance.
  3. Technology upgrades – Zero-knowledge proof (ZKP) solutions that allow verification of identity without exposing raw documents are gaining traction. Early adopters could gain a competitive edge by offering proof-of-identity that is auditable yet privacy-preserving.

A controversial take

The fintech community has long championed automation as the cure for slow, error-prone compliance. Revolut’s breach forces a hard look at that narrative: automation without robust, multi-factor checks is not a net benefit—it is a liability. The industry’s prevailing belief that “speed equals security” must be abandoned in favor of a “speed-with-checks” paradigm. Operators that double-down on rapid data release risk repeating Revolut’s mistake, while those that embed layered verification will set a new standard for responsible KYC.

In sum, the Revolut leak is more than a headline-grabbing breach; it is a symptom of systemic complacency in fintech compliance design. The lesson is clear: trust must be earned through multiple, independent signals, not merely by the appearance of a legitimate email address.

Explore more on this topic

Key takeaways

  • Revolut complied with a forged government email, exposing passports and Bitcoin transaction histories.
  • The incident shows how domain-authenticated emails can bypass manual verification in KYC workflows.
  • Operators must embed multi-factor validation and real-time threat intel to protect high-net-worth clients.

Questions

What data did Revolut disclose in the breach?

Passport copies, verification selfies, personal contact details and full Bitcoin transaction histories for a limited set of users.

How did the fraudulent request bypass Revolut’s controls?

The request originated from an email address that used a legitimate government domain and passed standard domain authentication checks.

Provenance

Published
September 13, 2026
Source dated
Sep 13, 2026
Original report
Decrypt
How this was made
Written up by an automated desk from the reporting linked above and published under the desk's name. Some outbound links are paid and are marked as partner links. How this site works.

More on this topic