Revolut has revealed a data breach where sensitive customer information was leaked after receiving a fraudulent request that appeared to come from a legitimate government agency This article explores identity theft. . The incident exposed highly sensitive Know Your Customer (KYC) documentation and detailed financial records for a limited number of users, including passport or driver’s license copies, identity-verification selfies, account statements, and complete transaction histories that included Bitcoin-related activity.
Instead, the company said it was targeted through a sophisticated impersonation operation involving an unauthorized email account operating under an official government agency’s email domain. The exposed document and verification data reportedly included copies of identity documents, such as passports and driving licenses, along with facial-verification images submitted during onboarding.
Revolut stated that biometric facial telemetry was not involved or compromised, but the loss of document scans and verification selfies could still pose serious identity-theft and impersonation risks for affected individuals. The inclusion of cryptocurrency transaction records, including Bitcoin activity, is particularly sensitive because it can help criminals profile victims' wealth, trading behavior, wallet usage, and potential exposure to targeted scams. On-chain investigator ZachXBT and other cryptocurrency luminaries revealed that the operation targeted high-net-worth users, a group with heightened risks of phishing, SIM-swapping, extortion, and highly tailored cryptocurrency theft attempts.












