Revolut leaked private customer data by fulfilling a fraudulent information request that originated from a legitimate government agency's email domain. The fintech company admitted that it shared ID documents, such as passports, and full cryptocurrency transaction histories for a limited number of users after failing to identify the request as unauthorized. Because the email was sent using an official government domain, the request appeared authentic to Revolut’s compliance team, bypassing internal red flags.
The incident underscores a growing security threat in 2026 known as 'Government Email Compromise' (GEC). In this specific case, attackers did not need to hack Revolut’s internal servers; instead, they successfully compromised or spoofed the communications of a government body to exploit the legal obligation fintechs have to cooperate with law enforcement. This resulted in the unauthorized exposure of 'Know Your Customer' (KYC) data and granular Bitcoin movement records, which are often used by bad actors to target high-net-worth individuals for phishing or identity theft.
From a regulatory standpoint, this breach is likely to trigger investigations into whether Revolut maintained adequate 'zero-trust' protocols for Law Enforcement Request (LER) processing. As US and international regulators tighten data privacy laws in early 2026, fintech platforms are under increasing pressure to verify the identity of the requesting official through secondary, 'out-of-band' channels rather than relying solely on the authenticity of an email domain.
For crypto users, the immediate impact involves heightened security risks for those whose transaction histories were exposed, as their wallet addresses are now linked to their real-world identities in the hands of attackers. Investors should watch for updates from Revolut regarding credit monitoring services for those affected and potential industry-wide shifts toward decentralized identity solutions that could prevent such centralized points of failure in the future.