Buy
Market
🔥
Prediction Market

How to Trace the Revolut Data Exposure Workflow

BiFu Editorial · 2026-09-13 · 4 min read


Table of contents

Revolut confirmed that a fraudulent information request sent from a legitimate government agency email domain triggered the release of customer passport scans and full Bitcoin transaction histories for a "limited" number of users.

Revolut confirmed that a fraudulent information request sent from a legitimate government agency email domain triggered the release of customer passport scans and full Bitcoin transaction histories for a "limited" number of users. According to separate reports from Decrypt, The Block, and BeInCrypto, the fintech company processed the request through standard compliance channels without detecting that the internal address was spoofed. The confirmed change is a single-point compromise of the KYC response process, not a broad systems intrusion.

Onchain investigator ZachXBT speculated that the attack may have targeted high-net-worth users, but neither Decrypt nor BeInCrypto independently verified that selection criteria. The exact number of affected accounts remains unspecified across all three reports, and no publisher has confirmed whether the attacker has used the leaked identity documents or transaction histories.

Before you start: map the affected request path

The affected workflow is Revolut's government-request response procedure. According to Decrypt, the fraudulent request arrived from the agency's own email domain, which made it appear legitimate to the compliance team. The Block reports that customer KYC and Bitcoin transaction data were exposed after the fake request. BeInCrypto confirms that Revolut sent passport scans and Bitcoin records in response to the email.

For any user who holds Bitcoin or has submitted KYC documents to Revolut, the operating consequence is direct: the controls that should distinguish a real subpoena from a forged one did not hold. The three publisher reports agree on this mechanism, even though they differ in framing. Decrypt emphasizes the data types released, The Block notes ZachXBT's high-net-worth speculation, and BeInCrypto confirms the disclosure itself.

Step sequence: trace the Revolut developments workflow

Step 1: identify the confirmed data release. Revolut sent passport scans and full Bitcoin transaction histories to the requester. All three sources confirm these data categories. The Block specifically names KYC data and Bitcoin transaction data, while BeInCrypto lists passports and Bitcoin records.

Step 2: isolate the verification failure. The request came from a government agency's own email domain, which bypassed standard verification checks. Decrypt reports this mechanism directly. The compliance team processed the request without further validation because the domain appeared legitimate. This is the confirmed workflow flaw.

Step 3: assess the affected participant pool. The "limited" number of users is not quantified in any publisher report. ZachXBT's speculation about high-net-worth targets, reported by The Block, narrows the risk profile but remains unverified. The shared operating impact applies to any Revolut user with KYC documents or Bitcoin transaction history, because the breach confirms that a single spoofed domain can trigger a full data release.

Step 4: separate confirmed changes from unresolved details. Confirmed: the data release occurred, the request used a legitimate government domain, and the exposed data included KYC documents and Bitcoin transaction histories. Unverified: the exact user count, whether high-net-worth accounts were specifically targeted, and whether any internal alert fired before fulfillment.

Checks: verify the unresolved data points

Check 1: the affected user count. Decrypt reports the exposure covered a "limited" number of users, while The Block and BeInCrypto did not provide a specific count. The operating impact changes materially if the breach affected dozens versus thousands of accounts. A source-document check against Revolut's official incident report or a regulatory filing is needed to confirm this figure.

Check 2: the targeting criteria. The Block reports that onchain investigator ZachXBT speculated the request may have been aimed at high-value users, but neither Decrypt nor BeInCrypto independently verified that targeting. Until a source document from Revolut or the investigator names the selection criteria, the targeting remains an unconfirmed detail.

Check 3: the complete data-field inventory. All three publishers agree that passport scans and Bitcoin transaction histories were included. The unresolved detail is whether KYC selfies, proof-of-address documents, or fiat transaction records were also sent. Revolut has not published a data-field list, so a full inventory of what left the system is the next fact to verify.

Limits: what the three reports do not establish

The three publisher reports do not establish whether Revolut has publicly revised its verification procedures since the incident. No source confirms a post-incident review, a change to the government-request response workflow, or an internal alert mechanism that would catch a spoofed domain in the future. Until Revolut releases a post-incident report or a regulatory filing with the confirmed user count and data categories, the breach cannot be treated as fully scoped.

For affected users, the immediate risk is that passport scans and complete crypto transaction histories are now exposed outside Revolut's control, enabling targeted phishing or identity theft. The risk taxonomy here includes operational-error risk in the verification workflow and custody risk for the identity documents held by the fintech. Users should treat any unsolicited communication referencing their passport or crypto history as potentially fraudulent, because the attacker now holds the same data that Revolut's compliance team released.

The next source-document check is whether Revolut has publicly revised its verification procedures, as no publisher has confirmed that step. If it has not, users should assume the same request-path gap remains open. The common operating impact across the three independent reports is that Revolut's verification workflow accepted a government-domain email as sufficient authority, releasing passport scans and Bitcoin transaction histories before the request was validated. This confirms the workflow flaw, not just a data leak.

Reference

  • https://decrypt.co/378114/revolut-passports-bitcoin-activity-data-breach
  • https://www.theblock.co/news/business/2026-09-12-revolut-says-customer-kyc-bitcoin-transaction-data-exposed-after-fake-request-from-govt-domain-414516
  • https://beincrypto.com/revolut-data-breach-fake-government-request

Read more from BiFu

Revolut confirmed that a fraudulent information request sent from a legitimate government agency email domain triggered the release of customer passport scans and full Bitcoin transaction histories for a "limited" number of users.

Learn More