How did a fake government request compromise Revolut Bitcoin transaction data?

Revolut was tricked into handing over sensitive personal information and Bitcoin histories after hackers successfully spoofed a legitimate government data request. This breach exposes high-net-worth users to identity theft and physical security risks by linking their real-world identities to their crypto holdings.
How did a fake government request compromise Revolut Bitcoin transaction data?

Revolut confirmed in early 2026 that a significant data breach occurred after the fintech giant treated a fraudulent government inquiry as a legitimate legal request. This sophisticated social engineering tactic allowed hackers to bypass traditional security protocols to access customer passports, driver’s licenses, and detailed Bitcoin transaction histories. The breach specifically targeted wealthy account holders, providing malicious actors with a direct map of both their fiat and cryptocurrency wealth distributions.

The disclosed data is remarkably comprehensive, encompassing verification selfies, home addresses, occupations, IBANs, and full account statements. For crypto-native users, the exposure of withdrawal records and complete transaction histories is particularly damaging, as it effectively deanonymizes their blockchain activity by connecting it to their government-issued ID and physical location. Affected customers were notified that their biometric data and financial footprints were compromised during the incident.

This incident highlights a dangerous trend in the 2026 threat landscape: "legal spoofing." As global regulatory frameworks have increased the frequency of legitimate data requests to exchanges, attackers are now exploiting the compliance departments of major financial institutions. By mimicking the administrative look and feel of a subpoena or a law enforcement inquiry, hackers can trick employees into bypassing technical firewalls that would otherwise block a direct cyberattack.

For the broader crypto market, this breach serves as a stark reminder of the privacy risks inherent in centralized neo-banks. While these platforms provide essential gateways for US-based investors, they also serve as centralized repositories of highly sensitive KYC data. The fact that Bitcoin histories were specifically included in the data haul suggests that attackers are increasingly looking for targets with high liquid crypto assets for further exploitation or extortion.

Investors and Revolut users should watch for upcoming regulatory probes into the platform's data handling policies and potential civil litigation from affected high-net-worth individuals. As hackers now possess the physical addresses and exact crypto balances of wealthy targets, there is a heightened risk of targeted phishing and physical security threats. The industry may now see a push for cryptographically signed government requests to ensure such a lapse in verification does not happen again.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.