Revolut Attackers Leak Passports and Bitcoin Records, Threaten Daily Dumps
September 14, 2026
A Fake Government Email Turns Revolut Into a Data Leak
Revolut has confirmed that it handed over sensitive customer records to an impersonator after receiving what appeared to be an official request from a government agency. The attackers are now publishing the material on Telegram and say more will follow every day until the bank pays. The London-based fintech described the incident as “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” according to Cointelegraph. It said its systems and customer funds were untouched and that a “limited number” of people were affected. The leak lands weeks after Revolut launched a euro stablecoin for its European crypto users, and it turns a routine compliance process, answering official data requests, into the weak point of a bank that markets itself on security.What the Attackers Have Published So Far
The group behind the leak has begun posting identity documents and verification selfies on Telegram, Cointelegraph reported on Monday. The first files belonged to at least two high-profile customers: a professional tennis player and the chief executive of an online crypto casino. Alongside the documents came a warning. “We’re going to start releasing more and more data every day until Revolut pays for leaking their customers,” the group wrote. No ransom figure has been made public, and Revolut has not said whether it is in contact with the group. The threat itself is the pressure: every day without payment exposes another batch of passports and account statements.How a Legitimate Government Domain Fooled the Bank
For a beginner, the mechanism is simpler than the word “hack” suggests. Banks and crypto platforms are legally required to respond to requests from police, tax authorities, and regulators, and those requests usually arrive via email from an official domain. This is the same reason platforms collect identity documents in the first place: Know Your Customer rules require them to verify the owner of each account. Revolut’s checks confirmed the emails came from a genuine government domain, suggesting the sender either controlled a real official mailbox or found a way to send from one. The domain passed, the request looked routine, and the data went out. Only later did the bank conclude the requests were not authentic. That is why the leak covers so much. A self-custody crypto wallet holds no passport copy, but a regulated account must, and a fraudulent request can ask for everything in the compliance file.
Passports, IBANs and Full Bitcoin Histories
The notification sent to affected customers listed names, dates of birth, occupations, postal and email addresses and phone numbers. It also covered copies of passports and driving licences, verification selfies, account statements with IBANs and wallet reference numbers, withdrawal records and complete transaction histories, including Bitcoin transfers. Revolut said biometric facial data was not included. It declined to say how many customers were hit or which government agency was impersonated. After spotting the scheme, the company blocked the sender’s address and alerted the relevant agency, along with law enforcement, data protection authorities, and financial regulators. Affected customers were contacted directly and offered support.Why Investigators Are Talking About Wrench Attacks
Blockchain investigator ZachXBT said the incident appeared limited in scale but seemed aimed at high-net-worth users. That detail worries security researchers more than the raw customer count. The combination of a Bitcoin transaction history, a home address and a face is exactly what physical attackers need. Chainalysis counted 46 violent “wrench attacks” on crypto holders in the first half of 2026, with more than $30 million stolen, putting the year on pace to beat the record $58 million taken in 2025, Cointelegraph reported in August. The firm found that victims are typically selected through data leaks, social media or insider information before any violence takes place. France offers the precedent. A breach at the tax platform Waltio exposed data on roughly 50,000 users, and the country logged 30 publicly known incidents by midyear. Coinbase faced a similar extortion attempt in May 2025 after bribed support contractors leaked customer records. The exchange rejected a $20 million ransom demand and instead offered a $20 million reward for information on the attackers.What Could Come Next for Revolut and Its Customers
Whether the attackers follow through on daily releases may decide how large the story becomes. Each new dump could identify further customers and increase pressure on Revolut to publish the numbers it has so far withheld. Regulatory questions are likely to follow. Revolut has notified data protection authorities, and under European and UK data rules, a leak of identity documents can trigger investigations that run for months. The company is also reported to be preparing for a stock market listing, which could raise the cost of any finding that its verification process was too easy to pass. Markets have so far shrugged. Crypto market prices rose on Monday, with Bitcoin trading near $78,000, suggesting traders view this as a customer-safety story rather than a threat to funds. For the people on the list, the risk is personal rather than financial, and it does not fade when the headlines do.KYC Files Have Become the Industry’s Softest Target
The most striking part of this incident is what it did not require. No malware, no exploit and no broken encryption. One convincing email to a compliance team produced a dossier that criminals would otherwise spend months assembling. Identity rules exist to keep criminals out of the financial system. This case shows the same rules building the files that criminals most want, stored by every regulated platform and released on request to anyone who can look, officially. Analysts note that the gap between a genuine data request and a fake one is now the thinnest line in fintech security, and Revolut is unlikely to be the last company asked to explain how it was crossed.
Share Article

Madiha Riaz
Madiha is a seasoned researcher in cryptocurrency, blockchain, and emerging Web3 technologies. With a background in organic chemistry and a sharp analytical mindset, she brings scientific depth to decentralized innovation. Since discovering crypto in 2017 and investing in 2018, she’s been uncovering and sharing deep insights into how blockchain is redefining the digital asset landscape.




