On Saturday 12 September 2026, Revolut confirmed a data breach that involved nobody hacking a server. Reuters reported that the British fintech disclosed sensitive customer information to an unauthorised third party after receiving fraudulent requests sent from a legitimate government agency email domain. Someone asked for the file, the request carried the right sender, and the file went out.
We make hardware wallets, so read the rest knowing we have a stake in the conclusion. The Revolut data breach is worth walking through anyway, because the interesting question is not how it happened. It is what the leaked package lets somebody do next, and which parts of your setup that package can reach.
What went out the door
Revolut's notification to affected customers listed birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences, according to Help Net Security. Verification selfies, account statements and transaction histories may also have been included. ZachXBT, the on-chain investigator who first published the notice, added several items the company's own summary left out: IBANs, withdrawal records, occupations, and transaction history covering Bitcoin.
Revolut says the number of affected customers is very limited and that all of them were contacted directly. A spokesperson told Reuters that "Revolut systems and customer funds are unaffected," and that the address was blocked as soon as the pattern was spotted, with the relevant government agency, enforcement agencies, data protection authorities and financial regulators all alerted. Recorded Future News reported that the people targeted skewed heavily toward high-net-worth individuals, many of them working in crypto, and that alleged extortion images circulated on Telegram by an account claiming responsibility pointed to an Italian domain. That account has since been suspended.
How a request like this passes the checks people rely on
Every piece of standard email hygiene assumes the sender is lying about who they are. Check the domain, check that the message passes SPF and DMARC, look for the lookalike spelling. None of that helps when the message comes from a mailbox on the actual government domain, because at that point the sender is exactly who the headers say. The forgery sits in the authority behind the request rather than the address in front of it.
Financial firms field these requests routinely and answer them under time pressure, which is the property being exploited. Whoever sent this one understood that an urgent-sounding enquiry from a recognised agency gets handled by someone whose job is to comply quickly. Revolut has not said publicly which agency's domain was used, and the broader question of whether the same mailbox was pointed at other institutions is open.
Why the Revolut data breach reads differently for crypto holders
For most customers a leak like this is an identity-theft problem, which is bad and also well understood. Freeze your credit, watch for account takeovers, expect a wave of phishing that knows your name. The crypto layer adds something that ordinary identity theft does not.
Start with the transaction history. A statement showing fiat moving out to an exchange, or Bitcoin purchases sized and dated, gives an analyst a set of timestamps and amounts to match against the chain. From there, clustering your on-chain addresses becomes a research task rather than a guess. Combine that with a home address and an occupation, and the attacker is no longer holding a list of email addresses. They are holding a shortlist of named people with an estimate of what each one holds and where each one sleeps.
That combination is why coercion attacks on crypto holders track leaked customer data so closely. Ledger's 2020 customer database leak is still generating threatening letters and home visits six years later, which is the durable lesson here: a breached address list does not expire, and there is no version of this where you get the documents back.
What the leaked file can and cannot reach
Here is the part worth being precise about, because overstating it would be easy. A leaked account statement does not contain a private key. Nobody signs a transaction with your passport scan. If your coins sit in self-custody behind a hardware wallet, this leak does not move them, and the balance that shows on a Revolut statement is a record of what you once bought rather than a key to where it went.
What the file does is tell someone where to aim. Every convincing scam runs on details the target assumes are private, and this package is a supply of exactly those details: the amount, the date, the phone number, the job. A call that opens with your correct balance and your correct address defeats the instinct that usually saves people, which is the vague feeling that the caller does not know enough about you to be legitimate.
The other thing worth saying plainly is that holding your own keys would not have prevented this leak. If you bought crypto through a regulated platform, that KYC record exists and will keep existing. Self-custody changes what the record is worth: it turns a live account someone can talk you into draining into a historical note about a purchase.
Where your backup sits in all of this
The move people make after a breach like this is to pull funds off the platform, and that instinct is right. It also relocates the problem, because now the thing standing between you and your crypto is whatever you wrote your recovery words on and wherever you put it. A paper card in a drawer survives roughly nothing. Stamped steel is the usual upgrade and a large improvement over paper, though your recovery still rests on one object that has to survive every scenario including a burglary by somebody who now knows your address.
TapSafe Recovery exists to take that single point of failure out of the picture. Recovery is split, with a Recovery Tag holding 50% and your paired phone holding the other 50%, stored encrypted in your iCloud or Google Drive instead of on the handset, so a lost phone does not cost you the share. Optional Recovery Contacts hold 25% each and can see nothing about your wallet. The split runs on a custom implementation of Shamir's Secret Sharing, and your seed phrase stays readable on the device as a last resort, on the BIP-39 standard, so you are never tied to our hardware. Because the Ryder One talks over NFC only and shows every transaction in full on its 1.6-inch AMOLED screen before you approve it, a caller who knows your balance still has nothing to work with.
What to do this week
If Revolut contacted you, treat the notification itself as a target: attackers follow a breach with emails that imitate the breach notice, so reach the company through the app rather than through any link you were sent. EU and UK customers can file a subject access request to get a documented list of what was disclosed, which is useful later if the data surfaces somewhere.
Beyond that, the work is unglamorous. Move anything you are holding long term into your own custody and stop treating an exchange balance as storage. Assume your address and your holdings are now linked in somebody's spreadsheet, and be careful about who hears about your crypto in person. Check that your recovery does not depend on one card in one drawer at the address that just leaked.
Ready to hold your keys without betting everything on one backup object? Get your Ryder One for 149 USD.
Meta description: The Revolut data breach sent IDs, statements and Bitcoin transaction history to a fake government request. What the leaked file reaches, and what it cannot.
Target keyword: revolut data breach




Share: