Press Enter to search · ESC to close

Regulation

Revolut Data Breach Exposes KYC and Bitcoin Transaction Data After Spoofed Government Request

Revolut has confirmed that customer KYC records and Bitcoin transaction data were exposed after attackers spoofed a government domain to submit a fraudulent data request. Onchain investigator ZachXBT suggested the breach may have targeted high-net-worth users, raising concerns about identity theft, wallet de-anonymization and regulatory fallout.

Revolut Confirms Breach of Customer KYC and Bitcoin Transaction Data

Revolut has disclosed that customer know-your-customer (KYC) records and Bitcoin transaction data were exposed after attackers impersonated a government domain to file a fraudulent data request. The incident underscores how social engineering against compliance channels — not just technical exploits — has become a primary attack vector for crypto platforms holding sensitive identity and wallet information.

How the Attack Unfolded

The breach stemmed from a fake request originating from a spoofed government domain, which appears to have bypassed verification procedures and led to the release of customer identity documents and Bitcoin transaction details. Onchain investigator ZachXBT speculated that the operation may have specifically targeted high-net-worth users, suggesting a calculated effort to harvest data on individuals holding significant digital assets.

The combination of KYC data and transaction history is particularly dangerous. KYC files typically contain passports, national IDs, proof of address and selfies — the raw material for identity theft, SIM-swap attacks and targeted phishing. Bitcoin transaction data, meanwhile, can be cross-referenced with public ledger records to map wallets, balances and counterparties, effectively de-anonymizing holders.

Why This Matters for the Industry

  • Compliance is now an attack surface. Regulators and law enforcement routinely request customer data; if platforms cannot robustly authenticate such requests, attackers will exploit the gap.
  • High-net-worth targeting. If ZachXBT’s assessment is correct, this is a precursor to “wrench attacks” and extortion, where criminals use leaked holdings data to physically or digitally coerce victims.
  • Regulatory scrutiny. Under GDPR and emerging crypto regulations such as MiCA, firms face potential fines and enforcement for failing to safeguard personal data.
  • Trust erosion. Revolut’s crypto users may reconsider how much identity and wallet information they entrust to centralized platforms.

Forward-Looking Perspective

This incident should accelerate adoption of hardened verification protocols for data requests: cryptographic signatures from government agencies, out-of-band confirmation, and audit trails. Firms may also move toward data minimization — storing less KYC data, tokenizing identity attestations, and using zero-knowledge proofs to satisfy compliance without retaining raw documents.

For users, the lesson is stark: centralized crypto platforms remain honeypots for identity and asset data. Expect increased demand for self-custody, privacy-preserving KYC solutions, and insurance products covering data breaches. Regulators, meanwhile, will likely tighten rules on how platforms respond to government data requests — turning a security failure into a broader compliance reform moment.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback