
Key takeaways
- Revolut says its systems and customer funds remain unaffected by the fraudulent request from a government domain disclosed this weekend
- Attackers published customer identity records and threatened daily releases until Revolut pays, according to their reported statement
- Exposed Revolut records include home addresses, verification selfies and Bitcoin transaction histories linked to customer identities
Revolut disclosed that customer information was exposed after it responded to a fraudulent request sent from a government domain. The exposed records included identity documents, home addresses, verification selfies, account statements and Bitcoin transaction histories. Revolut said its own systems were not compromised and customer funds were unaffected.
What the fraudulent request exposed
The disclosure linked personal identity records to financial information. Reporting on the incident named passports or other identity documents, home addresses, verification selfies, statements and Bitcoin transaction histories among the exposed data. That combination gave attackers something more dangerous than an anonymous transaction list: material connecting named customers to their own Bitcoin activity.
Revolut makes two claims: the fraudulent request came through a government domain, and its systems and customer funds were unaffected. Those two claims separate the disclosure of customer records from an actual breach of Revolut's own infrastructure or theft of customer money.
Revolut says its systems and funds stayed safe
Those statements draw a boundary around what the incident actually established. Sensitive customer records were disclosed. The reporting never showed that attackers got inside Revolut's systems or pulled money out of customer accounts.
The exposed Bitcoin histories carried a privacy risk of their own, because they sat right alongside identity documents, addresses and verification selfies. Put together, those records could connect a real person's identity and home address to their reported Bitcoin activity. That combination is what gave the attackers leverage.
Attackers threatened continuing releases
The attackers published customer information and threatened to release more data each day until Revolut paid, according to their reported Telegram statement. Their reported demand turned the disclosed records into an extortion instrument. The threat was not a claim that customer funds had been stolen; it was a threat to continue publishing identity and financial records.
The attackers' leverage came from publishing customer identities, addresses and Bitcoin transaction histories, not from any demonstrated access to customer balances. Their reported threat depended on how sensitive those records were, and on the prospect of daily repeated releases.
Why It Matters
The exposure joined identity documents and home addresses with Bitcoin transaction histories. That combination creates a privacy risk, even though Revolut said systems and funds were unaffected. The attackers reportedly threatened daily releases until Revolut paid. The incident showed how disclosed KYC records can become leverage without any wallet compromise or theft. For Bitcoin users, the concrete risk was the link between personal identity and transaction history inside the exposed records. Self-custody cannot undo identity leakage once KYC records and transaction histories have been disclosed together.



















