Revolut Hit by Social-Engineering Breach, KYC Data and Transactions Leaked

Revolut has confirmed a data exposure after responding to a request it believed came from a government agency—but which was later revealed to be part of a sophisticated impersonation attack. While no internal systems or customer accounts were hacked, the fintech firm has revealed that sensitive identity documentation and financial records belonging to a limited number of customers were handed over. This includes passport or driver’s license scans, identity-verification selfies, complete transaction histories (including Bitcoin activity), and other Know Your Customer (KYC) documents.

What happened and what was leaked

The incident stemmed from an email sent from a domain that appeared legitimate—matching credentials that digitally authenticated the domain. Revolut believed it was dealing with an authentic request under legal or official pretense, and so complied. The output was far reaching: customer full names, dates of birth, contact info, postal addresses, email addresses, telephone numbers, and employer details were among the data released. On top of that, identity document scans, selfie-verification images and full transaction statements—including those involving Bitcoin—were supplied.

Why this is so risky

Though Revolut insists that biometric facial recognition telemetry was not compromised, the loss of document scans and verification selfies poses serious risks of identity theft and impersonation. Combined with transaction histories and wallet references, attackers gain tools to build trustworthy social engineering messages or phishing lures. This is especially dangerous for users with substantial cryptocurrency holdings, as transaction behavior can be exposed and targeted.

Revolut has classified the breach not as a systems breach, but as a social engineering operation exploiting domain trust. After discovering the attack, it blocked the fraudulent email channel, alerted relevant authorities, and began notifying those affected. The company maintains that customer funds were never at risk.

Bigger picture: KYC risks and regulatory pressures

This episode revitalizes concern over the inherent hazards in KYC processes that require collecting deeply personal documents. Financial services, banks, exchanges and fintech allies often require these identifiers—but they now appear to be a high-value target for social engineering and impersonation efforts.

Particularly within crypto communities, high-net-worth individuals are highlighting that they are often the target of phishing, SIM swapping, extortion and highly tailored fraud. On-chain observers speculated that the Revolut incident may have aimed specifically at users with more visible crypto profiles.

Organizations that manage sensitive customer data are being reminded that domain credentials alone aren’t enough. Verifying high-risk requests through secondary channels—voice, in-person, or otherwise out-of-band—must be baked into procedures. Trust in domain authenticity doesn’t equal trustworthiness in every request.

Analyst verdict: this incident shows how much the human and procedural link in cybersecurity still matters. Even in airline-level fintechs with strong apps and infrastructure, vulnerability often lies not in the code, but in how we authenticate incoming requests. For Revolut users, watching for phishing and unexpected legal-looking messages is more than recommended—it’s essential. And for the industry, tightening processes around KYC-related requests could become a regulatory and reputational priority going forward.