The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Revolut Data Breach: Am I Affected, and What About My Bitcoin History?

After a forged government request, Revolut handed identity documents, account statements and complete Bitcoin transaction histories to an unauthorised party. Here is how to establish whether you are affected, and which protective measure actually achieves anything in this case.

An open passport booklet and a stack of account statements on a dark desk under a work lamp, with a metal coin bearing a Bitcoin stamp on top
14 min read
Share:

If you hold an account with Revolut and want to know whether the data incident of 11 and 12 September 2026 affects you, there are exactly two reliable routes: the notification the company sent to affected customers, and a subject access request of your own under Article 15 of the General Data Protection Regulation. Everything else is guesswork. Having received no message is not an all-clear; all it establishes is that no notification arrived.

This case differs from the breaches that usually occupy the industry. No server was broken into, no malware was planted and no password was cracked. An unauthorised party asked Revolut for customer data, and the request came in over the genuine, correctly authenticated email domain of a government agency. Revolut treated it as lawful and handed the documents over. For holders of Bitcoin that is particularly awkward, because the material released includes the complete transaction history.

What Revolut handed over, and what the company says remained untouched

The data categories come from CoinDesk's reporting of 12 September 2026, which draws on the notifications sent to those affected. They name passports and driving licences, the selfies from identity verification, names, dates of birth, occupations, home addresses, email addresses, phone numbers, IBANs, account statements, withdrawal logs and the entire transaction history including all Bitcoin activity.

Revolut told BeInCrypto that it had identified a sophisticated external identity attack in which an unauthorised third party submitted fraudulent information requests via the email domain of a legitimate government agency; systems and customer funds were unaffected. According to the company, police, data protection and financial supervisors were brought in, and the agency concerned was informed that an unauthorised account is operating inside its domain. Revolut does not say which agency, citing the ongoing investigation. The number of people affected also remains open; the company speaks of a limited number, and the investigator zachXBT, whose tip made the case public, described the target as a small circle of wealthy users.

What the notifications state explicitly did not leave: credentials, passcodes and the biometric templates behind facial recognition. That distinction matters, because it determines which protective measure achieves anything at all. An attacker who never had your password is not locked out by a new one.

How to tell whether you are one of the notified Revolut customers

Revolut says it wrote to affected customers individually; customer reports date those messages to 11 September 2026. There is no public list, and for good reasons there will not be one. The check is therefore yours to make.

The notification from Revolut and how it differs from a phishing email

A notification under Article 34 GDPR is a company's communication to affected individuals telling them that their data was exposed in a personal data breach carrying a high risk. It sets out the incident, the categories of data involved and the recommended measures. How you recognise one: a message of this kind does not ask you to enter credentials through a link, approve a payment or connect a wallet using a recovery phrase.

This is where the second wave begins. A breach of this kind produces forged messages within days that pose as the company's response, and this time the attackers hold names, home addresses, IBANs and account movements. That makes the fakes unusually credible. Check every incoming message inside the Revolut app itself rather than through a link in an email, and stick to the rules we set out in our guide to checking the genuine sender domain.

An Article 15 subject access request as documented proof

Article 15 GDPR gives you the right to ask a company what personal data it processes about you and to which recipients it has disclosed that data. It is the second part that matters here: the request forces a statement on whether your documents were part of the disclosure. The deadline is one month, extendable by a further two months in complex cases, and the company has to tell you if it extends.

Put the request in writing, name the incident with its date, ask explicitly about the recipients of your data, and request a copy of the notification if one was sent to you. Keep the reply. Anyone who later wants to bring a claim or lodge a complaint needs that correspondence as the foundation.

Why the Bitcoin transaction history is the most dangerous part of the package

An ID document can be replaced, an IBAN changed, a home address moved if it comes to that. The Bitcoin history, by contrast, points at a public database that nobody can take back. Whoever knows your deposits and withdrawals at a provider knows amounts, timestamps and, in many cases, the counterparties on the chain.

From the account statement to cluster analysis of your Bitcoin addresses

Cluster analysis is the technique of assigning several Bitcoin addresses to a single economic entity on the basis of shared characteristics, for instance because they appear together as inputs in one transaction. As long as nobody knows who a cluster belongs to, it stays an anonymous set of addresses. A withdrawal log with an amount and a timestamp supplies the missing anchor point, and from that moment the cluster carries a name and a home address.

An uncomfortable calculation follows. The attacker sees not only that you own Bitcoin, but can estimate through the linked addresses how much of it is still there and whether it is moving. We described what such a package of identity, home address and traceable wealth can lead to when we covered events in France: kidnappings and extortion with a crypto connection regularly started there with lists of exactly this kind.

An open bronze gate in a classical columned portal at night, a sealed envelope gliding through it unchallenged, a Bitcoin coin resting on the stone threshold
The request came through the real door: what was forged was not the domain, but the account writing from inside it.

Emergency data request: the mechanism behind the fake government enquiry

An emergency data request is a law enforcement request for information that a company answers on grounds of imminent danger, without a court order and without the scrutiny it would otherwise apply. The procedure exists because there are cases in which hours count. It has also been a known point of entry for years, because the only check is the judgement of an employee faced with an urgent enquiry that looks official.

The sequence is well documented in the specialist literature: someone gains access to an official mailbox or creates an account inside an agency domain, writes an urgent request for information from there, and receives the data because the recipient is trained to serve public authorities promptly. This is precisely the pattern Revolut describes in its statement when it speaks of an unauthorised account inside an agency's domain.

Why checking the sender domain, SPF and DMARC did not hold here

SPF, DKIM and DMARC are technical procedures that let the recipient of an email establish that it really was sent from the stated domain and was not altered in transit. These procedures answer a single question: does the message genuinely come from this domain? On whether the person behind the mailbox is authorised, they say nothing.

That is the counter-test to a recommendation we have issued ourselves. Checking the sender domain remains correct and catches the overwhelming majority of attacks. It only stops working at the moment an attacker controls an account inside the genuine domain, because then every technical check passes and nothing is right all the same. Anyone relying on that signal alone is mistaking a passed authentication for a passed authorisation check.

What changing your password after this data breach does, and what it does not

The usual advice after a breach runs: change your password, switch on two-factor authentication, check your devices. Here that is only half right, and the half that does not hold is the more important one. What left the company, according to the notifications, was not credentials but identity documents and account history. A new password takes nothing away from the attacker, because he never had the old one.

What genuinely helps is aimed at the follow-up attacks. That includes requiring a hard confirmation for withdrawals in the app, refusing phone enquiries from supposed staff on principle and hanging up, and assuming with every call that cites your real account details that those details may come from this incident. The caller who knows your last transfer is no longer proof that the call is genuine.

Immediate measures: identity misuse, account security, crypto holdings

The measures fall into two groups. One concerns your identity and makes sense regardless of whether crypto is involved. The other concerns your holdings and the question of where they should sit in future.

ID data cannot be recalled

A leaked scan of an ID document stays out there. What remains is observation: check your credit file regularly for enquiries and contracts you do not recognise, and have your bank explain its rules for opening accounts and changing addresses. Where a suspicion of identity misuse arises, it belongs in a police report, because establishing when the misuse happened later decides questions of liability. Germany's financial supervisor has already warned about this pattern; we have worked through the BaFin warning on identity misuse in the crypto sector in detail.

Home address plus Bitcoin holdings: take the physical risk seriously

The most unpleasant part of this package lies outside the digital world. Whoever holds a home address, a photo from an ID document and proof of wealth has everything needed for an attack at the front door. In practice that means: no public references to crypto holdings on social networks, no deliveries of hardware accessories to your home address, and no amounts named in conversation with acquaintances. Anyone self-custodying larger sums will find the devices that allow an access lock via an additional passphrase in our hardware wallet comparison, so that a coerced access does not release the entire balance.

This caution is not a panic reaction. It matches what those affected by earlier leaks in this industry have described in hindsight, and it costs nothing but habit.

A brass balance scale on dark stone, a heavy stack of bundled files on one side and a single Bitcoin coin on the other
Anyone who wants to complain needs the file first: obtain the disclosure, then bring in the supervisor.

Where German Revolut customers can complain

German customers are as a rule in a contractual relationship with Revolut Bank UAB, based in Lithuania and licensed as a credit institution by the Lithuanian central bank and the European Central Bank; alongside that, the company runs a German branch. For data protection, the provider's own privacy notice names the Lithuanian data protection authority as the lead supervisory authority. Check the details in your own contract documents, because the responsible entity can differ depending on the product and the date you signed up.

This order makes sense: first the Article 15 request to the company, then the complaint to a data protection authority once the reply has arrived or the deadline has passed. A complaint to the data protection authority responsible for where you live remains open to you under the General Data Protection Regulation; in cross-border cases it passes the matter to the lead authority. Without the prior correspondence, the complaint lacks its foundation.

How to reorganise your crypto holdings after a data breach

A data incident at a provider is a good occasion to review how your holdings are split, and to do it without haste. The decisive question is less which provider counts as the safest. The more useful thought is how much wealth needs to sit with any single provider at all. A trading account needs the amount that is actually being traded. Everything beyond that is a decision that could equally go the other way.

Self-custody means holding the private keys to your own coins yourself instead of entrusting them to a provider. That shifts the risk, it does not remove it: anyone self-custodying carries the risk of loss alone and needs a backup plan for the recovery phrase that survives a house fire and a house move. For many investors a split is the sensible middle path, with a small part kept ready to trade at the provider and the rest moving into self-custody.

The order matters here: the backup plan first, then the move. Anyone shifting balances in the agitation after bad news makes the most expensive mistakes of the year in that particular week.

What this case shows about KYC data at crypto providers and neobanks

KYC stands for "know your customer" and denotes the legally mandated identity check that banks and crypto service providers have to carry out before opening an account. That check is not negotiable, and at every regulated provider it creates a record made up of an ID photo, a selfie, an address and account movements. The Revolut case shows that the attack surface of this record is not made only of servers, but also of the procedures a company uses to answer requests for information.

A practical question for choosing a provider follows from that: how does the house handle official requests for information, does it publish figures on them, and how quickly does it inform those affected? Anyone looking for a new trading venue will find the providers licensed under the European supervisory framework in our overview of regulated crypto exchanges. A licence is not a promise of protection against this line of attack, but the assurance that a supervisor is responsible and reporting duties apply.

The incident joins a chain that has hit European crypto investors several times this year. The type of article is always the same because the questions are the same; our write-up on the Trezor data breach and how to check whether you were affected transfers step by step to this case.

Frequently asked questions about the Revolut data breach

Is my money at Revolut now at risk?

According to the company, systems and customer funds are unaffected by the incident, and none of the available sources contradicts that. The event is a release of documents to an unauthorised party, not access to accounts. The risk lies in what is attempted with those documents afterwards.

Do I have to change my Bitcoin addresses?

For the history already disclosed, changing addresses achieves nothing, because the past sits immutably in the chain. For future incoming payments it is still sensible to use new addresses and not to hold balances permanently on addresses that can be tied directly to a withdrawal from a provider account.

What about the claim of millions of Revolut records from the summer?

That is a different matter. The claim about a large-scale data set that surfaced on the darknet in July 2026 has no documented connection to the September request for information. Mixing the two is misleading, because the categories of data involved and the route of attack differ.

How do I know an email really comes from Revolut?

Reliably, not from the email alone. Open the app and check whether the same message is sitting in your inbox there. That rule carries more weight after this case than it did before, because a passed domain authentication simply does not prove authorisation.

Revolut data breach: what to take away

  1. Establish whether you are affected, do not estimate. Check in the Revolut app whether a notification is waiting, and independently of that file a subject access request under Article 15 GDPR with an explicit question about the recipients of your data. Anyone who wants to switch provider afterwards can shortlist candidates through the overview of regulated crypto exchanges.
  2. Decouple your holdings from your identity record. Decide what amount has to stay ready to trade at the provider, and move the rest into self-custody, with the backup plan in place before the move. The device selection including the passphrase function is in the hardware wallet comparison.
  3. Plan for the second wave. Expect calls and messages in the coming weeks that know your real account details, and treat every approach as unconfirmed until you have seen it in the app yourself. If you need a software solution for the part kept ready to trade, the software wallet comparison helps with the choice.

(As of September 12, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Sources: CoinDesk on the data categories involved and Revolut's statement to BeInCrypto.

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

More from CryptoTicker