ZeroHour
Cyber Security Newspublished ()ingested Guru Baran3· 1 read

Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers

highData breachimportance 62
AI summary · glm-5.3

Revolut leaked KYC documents and full transaction histories after a fraudulent, domain-authenticated email request impersonating a government agency.

Revolut disclosed that an attacker using an unauthorized email account on a legitimate government domain, with valid domain-authentication credentials, tricked the fintech into releasing customer data. The exposed data includes passport and driver's license copies, identity-verification selfies, full names, dates of birth, addresses, IBANs, and complete transaction histories including Bitcoin activity. Revolut says core systems, accounts, and funds were not compromised, and it blocked the email source and notified authorities. On-chain investigator ZachXBT and others indicated the operation targeted high-net-worth users facing elevated phishing, SIM-swap, and extortion risk.

  • Fraudulent request came from validly authenticated email on a government domain
  • Exposed KYC docs, verification selfies, IBANs, and full transaction histories
  • Cryptocurrency activity included, enabling victim wealth profiling
  • ZachXBT says high-net-worth customers were targeted
  • Revolut states funds and core systems were not compromised
Full article549 words · extracted from cybersecuritynews.com · click to collapse

Revolut has disclosed a data-security incident in which sensitive customer information was released after the financial technology company received a fraudulent request that appeared to originate from a legitimate government agency.

The incident reportedly exposed highly sensitive Know Your Customer (KYC) documentation and detailed financial records belonging to a limited number of users, including passport or driver’s license copies, identity-verification selfies, account statements, and complete transaction histories that included Bitcoin-related activity.

According to Revolut’s explanation, the disclosure did not result from a compromise of its core systems, mobile application, or customer accounts. Instead, the company said it was targeted through a sophisticated impersonation operation involving an unauthorized email account operating under an official government agency’s email domain.

Because the message carried valid domain-authentication credentials, Revolut believed it was handling an authentic legal or government information request and fulfilled it.

The response provided extensive information. It included customers’ full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers.

The exposed document and verification data reportedly included copies of identity documents, such as passports and driving licenses, along with facial-verification images submitted during onboarding.

Revolut highlighted that biometric facial telemetry was not involved or compromised, although the loss of document scans and verification selfies could still create serious identity-theft and impersonation risks for affected individuals.

Financial data included account statements containing IBANs, account status information, account-opening dates, wallet reference numbers, withdrawal records, and full transaction histories.

The inclusion of cryptocurrency transaction records, including Bitcoin activity, is particularly sensitive because it could help criminals profile victims’ wealth, trading behavior, wallet usage, and potential exposure to targeted scams.

Revolut described the event as a sophisticated social-engineering attack rather than a breach of its internal infrastructure. The company said it moved quickly to block the unauthorized email source, notify relevant authorities, and contact affected customers. It also maintained that customer funds remained safe and that its systems were not compromised.

However, the incident has triggered renewed concern over the security implications of mandatory KYC data collection across banks, fintech platforms, and cryptocurrency services. On-chain investigator ZachXBT and other cryptocurrency community figures highlighted claims that the operation targeted high-net-worth users, a group that faces elevated risks of phishing, SIM-swapping, extortion, physical threats, and highly tailored cryptocurrency theft attempts.

For impacted Revolut customers, the combination of identity documents, contact details, account information, and transaction history could provide attackers with the material needed to construct convincing social-engineering lures. Fraudsters may impersonate Revolut support staff, law-enforcement agencies, exchanges, or tax authorities while using personal information to make messages appear legitimate.

The case also demonstrates how trusted email domains can be abused when an attacker gains access to, or misuses, a legitimate organization’s mail infrastructure.

Even properly authenticated email can be malicious when the sender account itself is unauthorized. The incident underscores the need for organizations handling sensitive customer records to independently validate high-risk information requests through out-of-band channels, rather than relying solely on domain authentication or sender identity.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/revolut-data-breach/