Revolut Confirms Fake Email Leaked Passports and Bitcoin Data
The attack hit a limited group of customers and mainly affected identity and Bitcoin transaction data. Revolut says its systems and customer funds were not affected.

Key Takeaways
- Revolut confirms that an attacker used a fake message to request customer files, including passports, selfies, and Bitcoin records.
- The company says systems, customer funds, passcodes, login details, and biometric data were not affected.
- Revolut notified the customers involved, authorities, and regulators, while the police investigation into the government domain used in the attack continues.
Revolut has confirmed that an attacker was able to request customer files through a fake message, including passports, selfies, and Bitcoin records. According to the company, it was a sophisticated attack, but at its core it started with an email that appeared to come from a real government domain. Revolut says it blocked the sender right away after the issue was discovered.
Fake Email Looked Real
According to Revolut, an unauthorized third party used a government email address that looked legitimate to submit fraudulent requests. The company says its systems and customer funds were not affected. Passcodes, login details, and biometric data also were not exposed.
Still, the notices sent to customers paint a broader picture. They mention passports, driver’s licenses, home addresses, bank statements, and a full overview of Bitcoin transactions. Revolut is not saying which government domain was used because a police investigation is still ongoing.
What Exactly Leaked
The bank says only a limited group of customers was affected and that it has informed the people involved. Authorities, police, and data protection and financial regulators have also been notified. Blockchain investigator ZachXBT previously pointed to the leaks and said they involved a small group of users, possibly with wealthy customers in the mix.
The case fits into a broader wave of email fraud and impersonation attacks. Microsoft, for example, saw a sharp rise in business email compromise attacks in early 2026, a type of fraud where criminals pose as a trusted party to get information out of people. Regulators and cybersecurity firms also warn that these attacks are increasingly being paired with social engineering and stolen login credentials.
Other crypto companies show just how sensitive identity data is. KYC and ID systems remain an attractive target, precisely because those records reveal a lot more than just a password.
Why This Matters for Crypto
For crypto users, this is especially relevant because identity data and transaction history are often enough for targeted phishing. You can change a password, but you can’t change a passport number or home address. In crypto especially, where amounts and holdings can sometimes be visible or inferred, a data breach like this can make follow-up fraud even more dangerous.