Revolut data breach: how a fake government email handed attackers KYC selfies, passport scans, and full Bitcoin transaction history

The CyberSec Guru

Updated on:

Revolut Data Breach 2026

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

UPDATE

Revolut Breach Allegedly Far Larger Than Initially Reported, With 150 GB of Data Circulating Online

The Revolut incident has taken another major turn.

According to new reporting by la Repubblica, the data exposure connected to the compromised PEC account of the Prefecture of Reggio Calabria may be substantially larger than previously reported. The publication reports that approximately 150 GB of data has been disseminated online, allegedly including diplomatic passports and other sensitive documents.

If confirmed, the reported volume would represent a significant escalation from the earlier estimates of the incident, which focused on approximately 680 affected Revolut customers.

The development also raises fresh questions about the extent of the compromise of the Italian government infrastructure and the accuracy of earlier public descriptions of the incident.

150 GB of Data Reportedly Published Online

The latest reporting claims that a large dataset connected to the compromised government infrastructure has appeared online.

The reported material allegedly includes highly sensitive documents such as:

  • Diplomatic passports
  • Identity documents
  • Government-related records
  • Other sensitive personal information

The exact contents, provenance and authenticity of the entire 150 GB dataset have not yet been independently established in full.

If the reported figure and contents are confirmed, however, the incident would extend well beyond the customer-data disclosure originally associated with the Revolut investigation.

It would indicate that the compromised government account or associated infrastructure may have exposed a much broader collection of sensitive information.

New Questions About the Italian Government’s Response

The new reporting also puts renewed focus on the Italian government’s characterization of the incident.

📬 Stay Ahead of Cyber Threats

Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

Subscribe to the Newsletter →

Earlier statements and reporting had focused on the compromise of a government PEC account and its subsequent use in fraudulent requests sent to Revolut.

The latest allegations suggest that the underlying government-side compromise may have been considerably broader.

That creates an important question for investigators:

Was the compromised PEC account simply used as an impersonation channel, or did the attackers gain access to a substantially larger collection of government information?

At this stage, the full scope remains under investigation.

Claims that Italian authorities deliberately misrepresented the scale of the breach are allegations and should not be treated as established fact until supported by official findings or independently verified evidence.

Another Major Question: EU Regulation 2023/1543

The latest development also raises a legal issue concerning the European framework reportedly invoked in the fraudulent requests.

The attackers allegedly used Regulation (EU) 2023/1543, which establishes rules concerning European Production Orders and Preservation Orders for electronic evidence in criminal proceedings.

The regulation is designed to facilitate cross-border access to electronic evidence held by service providers.

However, the applicability of the regulation to financial institutions and particular categories of data is now being questioned.

Reports have pointed to Article 3 and the regulation’s scope as a potentially important issue.

If the fraudulent requests relied on a legal instrument that did not actually apply to the entity or information being targeted, that would add another layer to the incident beyond the compromise of the Italian government mailbox.

It would mean that the attackers may have combined a compromised government identity with a legal mechanism that appeared authoritative, creating additional pressure on the recipient organization to comply.

The exact legal interpretation and applicability of Regulation 2023/1543 in this specific case should ultimately be determined by the relevant authorities and courts rather than inferred solely from the leaked correspondence.

The Bigger Security Problem

The latest development reinforces the central issue already emerging from this incident:

The security of a legal data-request system depends on more than the authenticity of the communication channel.

A compromised government account can potentially provide an attacker with:

Trusted identity → official-looking correspondence → legal terminology → sensitive data access

That makes government email infrastructure itself a high-value security boundary.

The Revolut case demonstrates why organizations handling sensitive financial information cannot rely solely on the fact that a request originates from a legitimate institutional domain.

The requesting authority, individual, legal instrument, jurisdiction and scope of the request all need to be considered.

From a Revolut Breach to a National Cybersecurity Incident

The incident is therefore becoming broader than a conventional fintech data breach.

There are now potentially two interconnected security incidents:

  1. The compromise of an Italian government communication system.
  2. The subsequent disclosure of sensitive Revolut customer information through fraudulent requests.

The reported circulation of approximately 150 GB of additional government-related data, if verified, would make the first component particularly significant.

It would also raise questions about how long unauthorized access existed, what other systems or mailboxes may have been accessible, whether the attackers moved beyond the original PEC account, and exactly what information was exfiltrated.

Those questions remain open.

What We Know So Far

The publicly reported timeline now looks like this:

Government PEC compromised
↓
Attackers allegedly obtain control of an Italian institutional mailbox
↓
Fraudulent legal requests sent to Revolut
↓
Revolut allegedly releases sensitive customer information
↓
Requests continue for months
↓
Revolut discovers the correspondence is fraudulent
↓
Italian authorities open investigations
↓
Alleged attacker demands approximately $3 million in Monero
↓
Investigators obtain samples of allegedly stolen Revolut data
↓
New reporting claims approximately 150 GB of additional sensitive data has been published online

The final scope of the incident remains unclear.

This Story Is Still Developing

The reported 150 GB dataset, the identities of the attackers, the exact source of the newly disclosed documents, and the legal applicability of the cited European regulation all require further independent verification.

What is increasingly clear, however, is that the incident cannot be viewed solely as a conventional customer-data breach.

It involves the compromise of trusted government infrastructure, the alleged abuse of cross-border evidence procedures, the exposure of sensitive financial and identity information, and now claims of a much larger government-data leak.

We will continue updating this article as Italian authorities, Revolut, regulators and independent investigators confirm additional details.

Revolut Hacker Claims $3 Million Ransom Demand as New Evidence Emerges

The Revolut data breach has escalated significantly, with new information emerging about the alleged attack, the compromised Italian government email account, the type of customer information obtained, and a ransom demand reportedly made by the attacker.

An individual using the name “IAmNotAVillain” has reportedly demanded approximately 6,000 Monero (XMR), worth around $3 million, threatening to release or sell additional stolen customer information if the demand is not met within 24 hours. However, Revolut has said that no hacker has directly contacted the company with a ransom demand. The demand was instead published publicly by the alleged attacker.

Italian authorities are now investigating the incident. Prosecutors in Reggio Calabria have opened a case, while Italy’s Postal Police are investigating the compromised government PEC account. The National Anti-Mafia and Anti-Terrorism Directorate (DNA) has also been involved because a government communication channel is part of the investigation. This involvement does not establish that the attack was carried out by a mafia organization.

The precise identity of the person behind the keyboard also remains unconfirmed. References in some reports to “Italian hackers” should therefore be treated cautiously. What has been established publicly is that an Italian government communication channel was allegedly compromised and subsequently used to send fraudulent requests to Revolut.

The Compromised Government Account

New reporting has identified the allegedly compromised mailbox as belonging to the Prefecture of Reggio Calabria, specifically its Local Authorities office under Italy’s Ministry of the Interior.

The mailbox was reportedly associated with the pec.interno.it government domain.

This detail is significant because the attack allegedly did not depend on spoofing an Italian government address. Instead, the attackers reportedly obtained access to a legitimate institutional account and used it to communicate with Revolut.

That created a much more convincing impersonation scenario.

The alleged attacker reportedly had access to the mailbox for months, monitoring responses and controlling correspondence related to the fraudulent requests.

According to investigators who communicated with the alleged attacker, the actor claimed to have obtained government employee credentials through an infostealer. The attacker allegedly added a recovery email address, monitored the account and deleted messages that could reveal the unauthorized activity.

These operational details remain claims attributed to the alleged attacker and have not all been independently established by Italian authorities.

Fake European Investigation Orders

According to the latest accounts, the attackers allegedly used the compromised government account to submit multiple requests to Revolut over a period of several months.

The requests reportedly contained fake European Investigation Orders (EIOs) and asked Revolut to provide information associated with cryptocurrency transaction identifiers and wallet addresses.

Alleged Email Sent to Revolut by Attackers
Alleged Email Sent to Revolut by Attackers

The alleged strategy was to start with publicly available cryptocurrency information and then use Revolut’s KYC records to identify the individuals behind potentially valuable cryptocurrency holdings.

If the allegations are confirmed, the attack effectively turned publicly visible blockchain activity into a mechanism for identifying high-value financial targets.

The information reportedly obtained could include:

  • Identity documents
  • Passport information
  • Selfies used for verification
  • Residential addresses
  • Bank account information
  • IBAN details
  • Transaction histories
  • Cryptocurrency transaction information
  • Other KYC records

Reports have put the number of affected customers at approximately 680, although the final number should be confirmed by Revolut or the relevant authorities.

A Critical Procedural Question

One of the most significant questions now being raised concerns the authority of the office that allegedly issued the requests.

An European Investigation Order is a judicial instrument, and reports have questioned whether a Prefecture’s Local Authorities office would have the authority to issue an EIO requesting banking information from an institution in another EU member state.

This creates a distinction between two separate questions:

Was the email address genuine?

And:

Was the request itself legally valid and issued by an authorized authority?

A legitimate government mailbox can still be controlled by an unauthorized person, and a legitimate institutional domain does not by itself establish that a particular individual is authorized to demand sensitive customer information.

Alleged Five-Month Campaign

According to the latest investigation accounts, the fraudulent requests continued for approximately five months.

The alleged attacker reportedly submitted numerous requests, with Revolut allegedly responding to them and providing customer information.

In one alleged incident, the attacker reportedly submitted an incorrect document and received guidance from Revolut about how the request needed to be corrected.

If independently confirmed, this would raise additional questions about the human review process surrounding sensitive law-enforcement data requests.

At present, this particular allegation comes from material supplied by the alleged attacker and investigators and should not be treated as an established finding.

How Revolut Discovered the Fraud

The reported attack was eventually detected after Revolut identified anomalies in the requests and contacted the relevant Italian authorities through alternative communication channels.

The subsequent verification reportedly established that the legitimate government office was unaware of the requests being sent from its compromised mailbox.

The account was then blocked and the incident was reported to the relevant authorities and regulators.

This means the incident allegedly continued for months before an independent verification process revealed that the government correspondence was fraudulent.

New Evidence From the Alleged Attacker

Investigators at Duel say they have been communicating directly with the individual claiming responsibility for the breach.

According to Duel, the individual provided:

  • Videos showing allegedly stolen customer information
  • Original emails
  • Attachments
  • Screenshots
  • Samples of allegedly stolen files
  • Evidence intended to demonstrate control over the compromised correspondence

Duel also reported a dispute between two individuals using the names “Villain” and “Smilik”, with both claiming to be responsible for the breach.

According to Duel’s account, it considered the evidence supplied by Villain more convincing after comparing original emails, attachments and other material.

The identity of the actual attacker has not been publicly established by law enforcement.

Revolut Hackers Shared Data Breach of Revolut with Duel

High-Profile Customers Allegedly Included

Duel says samples of the allegedly stolen material contained information relating to several high-profile individuals, including:

  • A Swedish singer and Idol finalist
  • An Armenian academic
  • An Indian cricket star
  • Company founders and CEOs

Duel said it redacted personal information before publishing any material and deleted the original customer information it received.

The presence of samples does not, however, independently establish the total size or completeness of the alleged stolen dataset.

Why the Data Could Be Particularly Valuable

The alleged attackers appear to have focused on customers associated with cryptocurrency activity.

This makes the breach potentially more serious than a conventional customer-information leak.

A combination of verified identity information and cryptocurrency transaction history could allow criminals to associate a real person with blockchain activity that might otherwise be difficult to attribute.

The attackers could potentially use such information for:

  • Targeted phishing
  • Social engineering
  • Identity fraud
  • Cryptocurrency scams
  • Extortion
  • Selling information to other criminal groups

There have also been claims that some victims have faced serious threats because of the exposure of their financial information. Such individual claims should be independently verified rather than assumed to be directly caused by the breach.

The $3 Million Threat

The alleged attacker has reportedly placed a public ransom demand of approximately 6,000 XMR, or around $3 million, accompanied by a deadline.

The actor claims that individuals could potentially pay to prevent their information from being released and has threatened to sell or publish the data if the ransom is not paid.

Revolut, however, says that it has not received a direct communication from the hacker demanding payment.

This distinction is important: the existence of a public ransom demand does not necessarily mean Revolut has entered negotiations with the attacker.

The Security Question at the Center of the Incident

The emerging details point toward a fundamental security issue:

A trusted communication channel is not necessarily a trusted request.

Email authentication can establish that a message came through a legitimate institutional infrastructure.

It does not necessarily establish:

  • Who was operating the account
  • Whether the account had been compromised
  • Whether the sender was authorized
  • Whether the legal document was genuine
  • Whether the issuing authority had jurisdiction
  • Whether the requested data was proportionate to the investigation

For requests involving passports, financial records, selfies and cryptocurrency histories, investigators and cybersecurity professionals are therefore questioning whether an out-of-band verification step should have been used.

That could involve independently contacting the relevant government authority through a trusted telephone number or separate institutional channel rather than relying exclusively on the compromised email conversation.

Whether Revolut’s procedures met its legal and regulatory obligations will ultimately be determined through the ongoing investigations and regulatory reviews.

The Investigation Continues

The incident is now being examined from several angles:

  • The compromise of the Italian government PEC account
  • The authenticity and legal validity of the requests sent to Revolut
  • Revolut’s verification procedures
  • The number and categories of customers affected
  • The identity of the attacker or attackers
  • The amount of data allegedly obtained
  • The credibility of the ransom claims
  • Whether any stolen information has already been sold or distributed

The Italian investigation and regulatory reviews are ongoing.

For now, the case represents a particularly unusual form of data-exfiltration attack: instead of directly breaking into the financial institution, the alleged attackers appear to have abused a trusted government identity and an existing legal data-request process.

The original article below provides the earlier timeline and technical background. This update will be expanded as Revolut, Italian authorities, regulators and independent investigators publish additional verified information.

Update: Revolut Attacker Claims Broader Italian Law Enforcement Compromise

The Revolut incident may be broader than initially reported. International Cyber Digest says it is in contact with the threat actor behind the campaign, who allegedly claims that Revolut was only one target of a wider operation involving Italian law-enforcement infrastructure.

According to the claims reported by International Cyber Digest, the operation targeting Revolut was conducted over a period of approximately six months. The actor allegedly used access to Italian law-enforcement systems to send fraudulent information requests to Revolut, exploiting the credibility of legitimate government communications to obtain customer information.

The actor further claims to have compromised multiple Italian law-enforcement departments and allegedly possesses approximately 147 GB of data taken from those systems. The claimed material reportedly includes internal documents, calendars and personal information. Among the alleged material is reportedly a private conversation involving a law-enforcement officer and their spouse.

Update: Many Users Report Alleged Bitcoin Theft Following Revolut Incident

Update: The fallout from the Revolut data incident is also being followed by reports from users who claim that Bitcoin was stolen from their Revolut accounts shortly after the incident. These reports have raised concerns about whether information obtained during the attack may have been used in subsequent attempts to compromise or fraudulently access customer accounts.

Update: Revolut Data Incident Escalates as Threat Actor Demands Payment

Update: The Revolut data incident has taken a new turn, with a threat actor claiming to possess customer information and threatening to release additional data unless Revolut agrees to pay.

The development follows Revolut’s confirmation that an unauthorized third party obtained sensitive customer information through fraudulent requests impersonating a legitimate government authority. The incident highlights how attackers can exploit trusted communication channels and authentication mechanisms without necessarily compromising the underlying systems of the organization they are targeting.

According to information attributed to the attacker, the campaign involved an unauthorized email account operating within the infrastructure of a legitimate government agency. The fraudulent requests reportedly appeared to originate from genuine government infrastructure and carried valid domain authentication, leading them to be treated as legitimate requests for customer information.

The attacker is now claiming that the stolen information will be released progressively if Revolut does not meet its demands.

Threat Actor Threatens Further Releases

In newly observed messages, the alleged attacker claims that samples of customer information have already been published and threatens to release additional and potentially more sensitive information over time.

The actor reportedly stated:

«“We’re gonna start releasing more and more data everyday until Revolut pays for leaking their customers.”»

Alleged Threat Actor Claiming to Allegedly Leak Revolut User Data

The threat actor has also claimed that information belonging to high-profile Revolut customers could be exposed as part of the alleged disclosure campaign.

At this stage, claims made by the threat actor regarding the amount of information obtained, the identities of affected individuals, and the extent of any planned releases should be treated as unverified unless independently confirmed. The existence of a ransom demand or a claimed data release does not, by itself, establish the authenticity or completeness of all information being advertised.

Why This Development Matters

The reported escalation changes the nature of the incident from an initial unauthorized disclosure into a potential extortion and data-publication campaign. If additional genuine customer information is released, the exposed data could be used for targeted phishing, impersonation, account-takeover attempts, identity fraud, and other forms of social engineering.

The incident is particularly notable because the reported initial compromise did not rely on a conventional attack against Revolut’s public-facing infrastructure. Instead, the attacker allegedly abused the trust associated with legitimate government communications to persuade Revolut to disclose information.

That distinction is important. A valid email authentication result can demonstrate that a message was sent through an authorized domain or infrastructure, but it does not establish that the person operating the account was authorized to make the request. Attackers who gain control of, create, or otherwise abuse an account within a trusted domain can therefore use legitimate authentication mechanisms to make fraudulent communications appear considerably more credible.

As the situation develops, the key questions are how much customer information was actually obtained, which customers were affected, what information has genuinely been published, and whether further disclosures can be independently attributed to the incident.

Revolut customers should remain alert for targeted messages referencing their accounts or personal information and should verify unexpected requests directly through official Revolut channels rather than relying on links, phone numbers, or contact details contained in unsolicited communications.

A breach notification circulating among affected customers confirms that identity documents, facial verification selfies, IBANs, and complete transaction histories, including Bitcoin, left Revolut’s hands after the company was reportedly tricked by fraudulent government correspondence. Here’s what was exposed, why the notice’s wording matters legally, and what customers and fintechs should do next.

Original Article Continues Below

Sometime in the past 48 hours, Revolut customers began sharing a breach notification that reads less like a routine security update and more like an inventory of everything a bank knows about you. The notice lists four categories of compromised data: identity details (full name, date of birth, occupation), contact details (postal address, email, telephone number), document and verification data (copies of passports and driver’s licences plus the facial verification selfie submitted at onboarding), and financial data (account statements including IBAN, account status, opening date and wallet reference number, withdrawal records, and the full transaction history, Bitcoin included).

Posts summarising the incident on X were blunter than any press release: Revolut, users wrote, “got phished by some fake govt mail and they just handed over our data,” listing bank statements, selfies, wallets, and transaction history. If that holds up, this incident belongs to a class of breach that perimeter security can’t stop, because nothing was hacked in the traditional sense. The data was handed over by people who believed they were complying with an official request.

The timing makes this worse. It comes weeks after a threat actor advertised 75 million alleged Revolut records on a cybercrime forum for $500 (a claim Revolut disputed after finding no indicators of compromise and no valid identifiers in the samples), and months after a former employee allegedly tried to extort a customer by threatening to leak KYC data unless paid in cryptocurrency. Add a fraud wave in Jersey, where 75% of scam reports over four weeks involved Revolut accounts and roughly £180,000 was lost, and you get a threat ecosystem already primed to use exactly the kind of data this notification describes.

Alleged Geographic Scope Expands

The alleged scope of the Revolut incident may extend across multiple countries. Social-media reporting surrounding the threat actor’s claims has identified Germany, Italy, Spain, France, Switzerland, Malta, Cyprus, Ireland, the United Kingdom and Lithuania among the countries allegedly represented in the data.

According to the claims circulating online, Switzerland and France may account for a significant portion of the alleged data, although the exact distribution has not been independently established.

This geographic breakdown has not been confirmed by Revolut. The company has described the incident as affecting a very limited group of customers and has not publicly provided a country-by-country breakdown of those affected.

If the claims are subsequently validated, the international distribution would indicate that the incident was not confined to a single Revolut market. It would also help explain why customers in multiple European jurisdictions may receive notifications or encounter targeted phishing and social-engineering attempts related to the incident.

Revolut’s official statement is as follows from the email sent to affected users:

Revolut received a request for information disguised as a legitimate government agency request. The request originated from an unauthorized email account created directly within an official government authority’s domain infrastructure. The communication carried genuine domain authentication credentials leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request.

Once we became aware of the issue, we independently contacted the relevant government agency to validate the request, ultimately alerting the authority to the unauthorized account apparently operating within their domain. Upon confirming the compromise, Revolut immediately blocked the address across all internal systems, initiated notifications to relevant regulators, and applied precautionary protection measures for affected customers.

What we know, and what is still reported rather than confirmed

Let’s be precise about attribution, because breach coverage collapses when speculation hardens into fact. What is documented: affected customers received a notification enumerating the four data categories above, including the explicit statement that “no biometric facial telemetry data was involved or compromised.” Screenshots of that notice and of customer posts describing a fake-government-email phishing vector began circulating publicly on September 11 to 12, 2026. What is not yet independently confirmed in indexed reporting: the number of affected customers, the specific government body impersonated, and the internal workflow through which the data was released. At the time of writing, the most detailed primary account of what was taken is the notification itself, so we’re treating the “fake government mail” vector as a well-sourced customer report rather than a company confirmation.

The data categories in the notice are specific, internally consistent with Revolut’s product set (IBANs from its Lithuanian-licensed banking entity, wallet references and Bitcoin history from its crypto custody service), and materially more sensitive than anything exposed in the company’s 2022 incident. Whether the handover originated with a phished support agent, a compromised back-office mailbox, or a manipulated legal-request process, the outcome is identical: a complete KYC and financial dossier on an unknown number of customers now sits outside Revolut’s control.

Revolut Data Breach Email
Revolut Data Breach Email

The attack vector: why “handed over” is more dangerous than “hacked”

Most breach post-mortems describe an intrusion chain (initial access, persistence, lateral movement, exfiltration), and each stage leaves telemetry that detection engineering can catch. A social-engineering handover inverts that model. The attacker sends correspondence impersonating a government authority (a regulator, tax agency, or law enforcement body issuing what appears to be a lawful demand for customer records), and an employee trained to cooperate with official requests complies. Every action in the chain is authorised: the mailbox login is legitimate, the database query is legitimate, the export is legitimate. EDR never fires, because from the infrastructure’s point of view, work is simply being done.

This is why government-impersonation phishing has become a priority threat against regulated industries. The pretext exploits the one behaviour security awareness training struggles to eliminate: deference to authority under time pressure. It targets the process rather than the password. Multi-factor authentication is irrelevant when the credential was never stolen; the attacker never needed a session cookie because the data arrived as an attachment. Revolut has form here: its September 2022 breach, which exposed 50,150 customers’ names, addresses, email addresses, phone numbers, partial card data, and past transactions, began with a phished employee credential and a “highly targeted” social-engineering campaign, and was subsequently investigated by Lithuania’s State Data Protection Inspectorate, the lead supervisory authority for Revolut’s EEA entities.

The 2026 twist is the payload. Four years ago, attackers walked away with contact details and masked card fragments: useful phishing fuel, but limited. This time, according to the notification, they walked away with the onboarding file itself: the government-grade identity proof and the live face image that banks and other exchanges use to decide whether an applicant is really you.

Inside the notification: a category-by-category risk analysis

The notice’s four data points breached are as follows:

Identity details: full name, date of birth, occupation

On their own these are commodity data. Combined with the rest of the package they become the skeleton of a synthetic identity: enough to answer knowledge-based verification questions at other institutions, to pre-fill credit applications, and to make every subsequent phishing contact feel bureaucratically authentic. Occupation is an underrated field here: it tells a fraudster whether you’re worth a business email compromise campaign, whether a “payroll update” pretext will land, and which institutions you’re likely to hold accounts with.

Contact details: postal address, email address, telephone number

This is the targeting layer. Physical address enables interception-based fraud and lends credibility to vishing calls (“we’re calling about your account at [your street]”). The email and phone number are the delivery channels for the follow-on campaign, and history shows these arrive fast: after the 2022 breach, a phishing wave hit Revolut’s entire customer base, not just the 50,150 affected, using real account attributes to manufacture trust.

Document and verification data: passport or driver’s licence copies plus the onboarding selfie

This is the crown-jewel category, and the reason this story matters beyond Revolut’s customer base. A high-resolution scan of a passport or driver’s licence is a forgery kit: the document template, security-feature layout, and a victim’s biographic data are everything a counterfeit operation needs. The selfie is more damaging still. KYC selfies exist to prove that a live human matches the document; in criminal hands, the same image trains presentation attacks against liveness detection elsewhere. Telegram-based KYC-bypass services already sell deepfake injection tooling that feeds synthetic faces or replayed video into identity-verification SDKs on jailbroken devices, and the broader market has been reinforced by mega-leaks of verification imagery, from the IDScan.net-style driver’s licence dumps to the nine-million-image facial-recognition breach reported in August 2026. A leaked selfie doesn’t expire, can’t be rotated, and now travels with the exact passport it was matched against.

The notification’s careful rider, “no biometric facial telemetry data was involved or compromised,” is a legally loaded sentence. We unpack it below.

Financial data: IBAN, account status, opening date, wallet reference, withdrawal records, full transaction history including Bitcoin

Read this list as an attacker’s dossier and it’s close to complete. The IBAN enables fraudulent SEPA direct-debit mandates (victims have refund rights, but only if they notice within the windows). Account status and opening date are precisely the facts a support-desk social engineer needs to pass verification at Revolut or at correspondent institutions. The wallet reference number is the join key between the fiat file and the crypto file: it ties the internal custody account to the customer record. Withdrawal records reveal liquidity and cash-out rhythm: when you have money and when you move it, the exact targeting data extortionists prize. And the full transaction history, Bitcoin included, does the most irreversible damage of all: it permanently binds your legal identity to your on-chain pseudonyms.

“No biometric facial telemetry was compromised”: reading the fine print like a regulator

That clause isn’t marketing. It’s a GDPR boundary marker. Under Article 9, biometric data processed to uniquely identify a person is a special category attracting heightened protection and heavier penalties. A raw selfie is an image; a biometric template (the mathematical feature map, liveness scores, and depth or motion telemetry a verification SDK generates when it analyses that image) is biometric data in the strict sense. By stating that no telemetry was involved, Revolut is asserting that the exposed asset is the photograph, not the derived template, and therefore that the incident doesn’t constitute a special-category biometric breach.

The distinction is legally real and practically thin. Attackers don’t need your feature vector to impersonate you; they need pixels. A stolen selfie plus a stolen passport scan supports document replays, face-swap injection into verification flows, and the synthesis of convincing video for vishing-adjacent scams. Regulators, including European data protection authorities following EDPB guidance on facial recognition, assess risk by what the data enables, not by its format. Expect the Lithuanian State Data Protection Inspectorate, which published details of the 2022 breach and opened a formal investigation into Revolut’s handling of it, to test exactly that point if this notification triggers an Article 34 assessment, and its specificity suggests it has.

The Bitcoin problem: why “including Bitcoin” is the sentence crypto holders should reread

Bitcoin’s ledger was always public; privacy on-chain was never about hiding transactions but about hiding who owns the addresses. Every defence a holder relies on, address rotation, separation of funds, pseudonymous wallets, depends on the identity-to-address map staying secret. A leaked transaction history from a KYC’d custodian destroys that secrecy in one document: it states which verified individual controlled which wallet references, when funds arrived, how large the positions were, and where they went.

Because blockchains are append-only, that linkage can’t be undone. Chain-analysis techniques such as common-input-ownership clustering and change-address heuristics let anyone who holds the identity map extend it forward across years of future transactions. The practical consequences are unglamorous and severe: dusting and targeted-phishing campaigns aimed at known holders, extortion lists sorted by balance, and, as the February 2026 case showed, when a trader alleged a former Revolut employee threatened to publish his KYC file and contacted his relatives unless a crypto ransom was paid, blackmail material that arrives pre-verified by the institution itself. Revolut reported that matter to law enforcement and maintained that its controls operated as intended; the alleged incident nonetheless showed attackers pricing KYC dossiers as ransom assets months before this notification existed.

Revolut’s incident timeline

One breach is an event; four is a trend. The record, as publicly reported:

DateIncidentReported impact
Sept 2022Social-engineering attack; phished employee credential; database access50,150 customers (0.16%); contact + partial card data + past transactions; Lithuanian SDPI investigation
July 2023Exploited flaw in US payment processing~$20M stolen via erroneous refunds
Feb 2026Alleged extortion by former employee threatening KYC leakIndividual customer targeted; crypto ransom demanded; referred to law enforcement
July 2026Forum listing claiming 75M records for $500Revolut found no breach indicators; researchers suspect aggregated/fabricated data
Aug to Sept 2026Jersey vishing wave impersonating Revolut fraud teams75% of scam reports over 4 weeks; ~£180,000 lost
Sept 2026Fake-government-email phishing; customer data handover (this incident)KYC documents, selfies, IBANs, full txn history incl. Bitcoin; scale unconfirmed

Read together, the timeline shows both sides of the modern threat model converging on the same asset: outsiders phishing their way toward customer records, and insiders (or ex-insiders) treating those records as saleable inventory. It also shows the follow-on economy working exactly as designed: breached attributes from earlier incidents supplied the authenticating detail for the Jersey vishing campaigns.

ZachXBT's Notification Regarding Revolut Data Breach
ZachXBT’s Notification Regarding Revolut Data Breach

Regulatory exposure: GDPR, DORA, and the Lithuanian supervisory chain

Revolut’s EEA operations run through Lithuanian-licensed entities supervised by the Bank of Lithuania and the ECB, with the State Data Protection Inspectorate acting as cross-border lead supervisory authority for data protection, which is where Articles 33 and 34 of the GDPR bite. A breach of this sensitivity (identity documents, facial images, complete financial history) sits squarely in “high risk” territory, obliging communication to affected data subjects in clear language. The notification’s plain-English category list is, to its credit, exactly what Article 34 contemplates, and a marked improvement on the vaguer 2022 emails that drew customer criticism at the time.

Beyond GDPR, Revolut Bank UAB is in scope for DORA (Regulation (EU) 2022/2554), which forces major ICT-related incident reporting and, more importantly for this case, demands that operational risk from social engineering of critical processes be governed, tested, and documented. UK-facing operations add FCA principles and UK GDPR obligations overseen by the ICO, which was also engaged in 2022. The sanction ceiling (up to 4% of global turnover or €20 million under GDPR, whichever is higher) is theoretical; the realistic costs are compulsory remediation, supervisory scrutiny of the legal-request workflow, and civil claims under Article 82 for material and non-material damage, which collective-claims firms will already be scoping.

If you received this notification: a prioritised response checklist

Treat the next 90 days as a hostile information environment. Work top to bottom.

  • Assume every inbound contact is fraudulent until proven otherwise. Revolut will not call to ask for codes, passwords, or approvals. Anyone who does is attacking you, and they now know enough about your account to sound legitimate. Verify through the app’s official chat or a number you typed in yourself.
  • Harden the account itself. Enable app biometric lock and a strong passcode, move your email to a unique password with phishing-resistant 2FA (a passkey or hardware key, not SMS), and review active sessions and linked devices.
  • Register for fraud protection. In the UK, consider CIFAS Protective Registration; in the US, freeze your files at all three bureaus; elsewhere, set credit-file alerts. Your name, DOB, and address are now a pre-approved application kit.
  • Watch the rails, not just the balance. Set transaction alerts, scrutinise statements for unfamiliar SEPA direct debits (unauthorised debits carry a 13-month claim window; authorised-but-contested ones, eight weeks), and never move money to a “safe account,” which doesn’t exist.
  • Treat your on-chain history as attributed from now on. Use fresh receiving addresses, ignore dust transactions and “wallet verification” messages, avoid discussing holdings in any channel, and if you hold materially, review your operational security with the assumption that your balance range is known.
  • Monitor for identity misuse for a year. Unexpected credit declines, collection letters, or tax correspondence in your name are the lagging indicators of document fraud, so check your credit file quarterly.
  • Preserve evidence and know your rights. Keep the notification, log every suspicious contact, and remember that GDPR Article 82 gives you a compensation route and Article 77 a complaint route to your supervisory authority.

What fintechs must fix: KYC stores are crown-jewel data, and they’re managed like attachments

For security leaders, this incident is a control-design case study. Start with the request channel: any email asserting government or regulator authority should be unverified by default, answered only through pre-registered out-of-band channels (a callback to a published switchboard, an authenticated regulator portal, or a signed-correspondence register), with dual-control approval before a single record leaves the building. Then fix the egress path: bulk exports of KYC media from support consoles should be technically difficult, ticketed, approved, and alerted on, because a handover breach is caught by data-loss prevention and access analytics, not by endpoint tooling.

Retention is the third lever, and the one nobody wants to pull. AML rules require keeping records, but they don’t require keeping every artefact in its most dangerous format forever: extract the data fields, verify the document and face, then apply a minimisation schedule, watermarked, access-logged, tightly permissioned storage for images, with raw selfies and templates purged once the verification decision is final and the retention basis expires. Layer on phishing-resistant MFA for staff, vishing and quishing drills that include the legal-request desk, anomaly detection for burst reads against KYC object stores, and dark-web monitoring that treats KYC-pack listings (genuine or fabricated, as July’s $500 claim showed) as an early-warning feed. Firms that get ahead of the next decade of identity fraud will be the ones that stop treating onboarding imagery as a by-product and start treating it as the most dangerous material they hold.

Frequently asked questions

Was my money stolen in this Revolut breach? There’s no evidence that funds were accessed or moved; the exposure is data, not balances. The financial risk is indirect but real: the stolen attributes are precisely what fraudsters use to engineer transfers, approve debits, and take over accounts elsewhere.

How do I know if I’m affected? Revolut is notifying affected customers directly, and the notification enumerates the exact categories taken. If you haven’t received one, you’re likely outside this incident’s scope, but stay alert, because follow-on phishing after Revolut breaches has historically targeted the whole customer base, not only the compromised subset.

What does “no biometric facial telemetry was compromised” actually mean? It means the derived biometric artefacts (feature maps, liveness scores, measurement data generated during verification) weren’t touched; only the raw selfie image was. Legally that keeps the incident outside GDPR Article 9’s special-category biometric regime; practically, the image alone still enables deepfake and presentation attacks.

Can a leaked selfie and passport scan be used to open accounts in my name? Yes. Forgery tooling and deepfake injection kits that defeat liveness checks on verification SDKs are commercially available on criminal markets, which is why fraud alerts and credit-file monitoring matter more than password changes after a breach like this.

Is my Bitcoin transaction history now public? The ledger was always public. What’s changed is that your verified identity is now linked to your wallet references and history in criminal hands. That linkage is permanent and extends forward to future transactions through standard chain-analysis clustering.

Can I claim compensation? GDPR Article 82 provides for compensation for material and non-material damage caused by an infringement, and Article 77 lets you complain to a supervisory authority, the Lithuanian State Data Protection Inspectorate for EEA customers, the ICO for UK customers. Keep records of any fraud or distress you suffer as a result.

The bottom line

Every ingredient of this incident has been visible for years: KYC files as the single most valuable object in the fraud economy, government impersonation as a phishing pretext that defeats MFA without ever touching it, and blockchain permanence turning one leaked statement export into a lifelong identity-to-wallet map. What’s new is the completeness of the package described in Revolut’s notification: document, face, fiat history, and crypto history in one handover. For customers, the response is disciplined skepticism and monitoring, because the data can’t be un-leaked. For the industry, it’s a reminder that the weakest link in a bank’s security architecture is still the well-meaning employee holding a letter that looks official, and that the strongest defense is a process where no single human, and no single email, can move a customer’s identity out the door alone.

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading