Revolut has officially confirmed that a targeted phishing attack using fake government credentials resulted in the exposure of customer passports and specific Bitcoin holdings records. The breach occurred after attackers sent highly convincing emails appearing to be from official regulatory bodies, tricking users into revealing access to their account data. While Revolut clarified that the integrity of its internal wallets remains intact and no funds were drained, the exfiltration of Bitcoin-specific data creates a significant privacy risk for affected users.
The attack specifically targeted the intersection of KYC (Know Your Customer) data and digital asset history, which is a high-value target for 2026 cybercriminals. By gaining access to passport details alongside Bitcoin transaction logs, hackers have effectively created a map of high-net-worth individuals and their crypto footprints. Revolut’s security team identified the breach after noticing unusual data access patterns, but not before the information of a specific segment of the user base was successfully harvested.
This incident follows a trend in 2026 where fintech platforms are being targeted not just for direct theft, but for information that can be used in secondary extortion or targeted identity theft. US regulators, including the CFPB, are expected to investigate whether Revolut’s encryption standards for crypto-linked data met current compliance requirements. This breach could potentially delay Revolut's planned expansion of advanced DeFi features if the company is forced to undergo mandatory third-party security audits.
For the broader market, this event highlights the persistent risks of centralized crypto exchanges and fintech apps. While Bitcoin’s price has not reacted significantly to the news, the breach serves as a stark reminder of the importance of self-custody and the vulnerabilities inherent in platforms that store large amounts of sensitive PII (Personally Identifiable Information) alongside transaction data. Users are advised to remain vigilant against follow-up phishing attempts that may use their stolen passport details to appear more legitimate.