Revolut Data Breach: Am I Affected, and What About My Bitcoin History?
After a forged government request, Revolut handed identity documents, account statements and complete Bitcoin transaction histories to an unauthorised party. Here is how to establish whether you are affected, and which protective measure actually achieves anything in this case.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If you hold an account with Revolut and want to know whether the data incident of 11 and 12 September 2026 affects you, there are exactly two reliable routes: the notification the company sent to affected customers, and a subject access request of your own under Article 15 of the General Data Protection Regulation. Everything else is guesswork. Having received no message is not an all-clear; all it establishes is that no notification arrived.
This case differs from the breaches that usually occupy the industry. No server was broken into, no malware was planted and no password was cracked. An unauthorised party asked Revolut for customer data, and the request came in over the genuine, correctly authenticated email domain of a government agency. Revolut treated it as lawful and handed the documents over. For holders of Bitcoin that is particularly awkward, because the material released includes the complete transaction history.
What Revolut handed over, and what the company says remained untouched
The data categories come from CoinDesk's reporting of 12 September 2026, which draws on the notifications sent to those affected. They name passports and driving licences, the selfies from identity verification, names, dates of birth, occupations, home addresses, email addresses, phone numbers, IBANs, account statements, withdrawal logs and the entire transaction history including all Bitcoin activity.
Revolut told BeInCrypto that it had identified a sophisticated external identity attack in which an unauthorised third party submitted fraudulent information requests via the email domain of a legitimate government agency; systems and customer funds were unaffected. According to the company, police, data protection and financial supervisors were brought in, and the agency concerned was informed that an unauthorised account is operating inside its domain. Revolut does not say which agency, citing the ongoing investigation. The number of people affected also remains open; the company speaks of a limited number, and the investigator zachXBT, whose tip made the case public, described the target as a small circle of wealthy users.
What the notifications state explicitly did not leave: credentials, passcodes and the biometric templates behind facial recognition. That distinction matters, because it determines which protective measure achieves anything at all. An attacker who never had your password is not locked out by a new one.
How to tell whether you are one of the notified Revolut customers
Revolut says it wrote to affected customers individually; customer reports date those messages to 11 September 2026. There is no public list, and for good reasons there will not be one. The check is therefore yours to make.
The notification from Revolut and how it differs from a phishing email
A notification under Article 34 GDPR is a company's communication to affected individuals telling them that their data was exposed in a personal data breach carrying a high risk. It sets out the incident, the categories of data involved and the recommended measures. How you recognise one: a message of this kind does not ask you to enter credentials through a link, approve a payment or connect a wallet using a recovery phrase.
This is where the second wave begins. A breach of this kind produces forged messages within days that pose as the company's response, and this time the attackers hold names, home addresses, IBANs and account movements. That makes the fakes unusually credible. Check every incoming message inside the Revolut app itself rather than through a link in an email, and stick to the rules we set out in our guide to checking the genuine sender domain.
An Article 15 subject access request as documented proof
Article 15 GDPR gives you the right to ask a company what personal data it processes about you and to which recipients it has disclosed that data. It is the second part that matters here: the request forces a statement on whether your documents were part of the disclosure. The deadline is one month, extendable by a further two months in complex cases, and the company has to tell you if it extends.
Put the request in writing, name the incident with its date, ask explicitly about the recipients of your data, and request a copy of the notification if one was sent to you. Keep the reply. Anyone who later wants to bring a claim or lodge a complaint needs that correspondence as the foundation.
Why the Bitcoin transaction history is the most dangerous part of the package
An ID document can be replaced, an IBAN changed, a home address moved if it comes to that. The Bitcoin history, by contrast, points at a public database that nobody can take back. Whoever knows your deposits and withdrawals at a provider knows amounts, timestamps and, in many cases, the counterparties on the chain.
From the account statement to cluster analysis of your Bitcoin addresses
Cluster analysis is the technique of assigning several Bitcoin addresses to a single economic entity on the basis of shared characteristics, for instance because they appear together as inputs in one transaction. As long as nobody knows who a cluster belongs to, it stays an anonymous set of addresses. A withdrawal log with an amount and a timestamp supplies the missing anchor point, and from that moment the cluster carries a name and a home address.
An uncomfortable calculation follows. The attacker sees not only that you own Bitcoin, but can estimate through the linked addresses how much of it is still there and whether it is moving. We described what such a package of identity, home address and traceable wealth can lead to when we covered events in France: kidnappings and extortion with a crypto connection regularly started there with lists of exactly this kind.

Emergency data request: the mechanism behind the fake government enquiry
An emergency data request is a law enforcement request for information that a company answers on grounds of imminent danger, without a court order and without the scrutiny it would otherwise apply. The procedure exists because there are cases in which hours count. It has also been a known point of entry for years, because the only check is the judgement of an employee faced with an urgent enquiry that looks official.
The sequence is well documented in the specialist literature: someone gains access to an official mailbox or creates an account inside an agency domain, writes an urgent request for information from there, and receives the data because the recipient is trained to serve public authorities promptly. This is precisely the pattern Revolut describes in its statement when it speaks of an unauthorised account inside an agency's domain.
Why checking the sender domain, SPF and DMARC did not hold here
SPF, DKIM and DMARC are technical procedures that let the recipient of an email establish that it really was sent from the stated domain and was not altered in transit. These procedures answer a single question: does the message genuinely come from this domain? On whether the person behind the mailbox is authorised, they say nothing.
That is the counter-test to a recommendation we have issued ourselves. Checking the sender domain remains correct and catches the overwhelming majority of attacks. It only stops working at the moment an attacker controls an account inside the genuine domain, because then every technical check passes and nothing is right all the same. Anyone relying on that signal alone is mistaking a passed authentication for a passed authorisation check.
Hold your coins safely in self-custodyWhat changing your password after this data breach does, and what it does not
The usual advice after a breach runs: change your password, switch on two-factor authentication, check your devices. Here that is only half right, and the half that does not hold is the more important one. What left the company, according to the notifications, was not credentials but identity documents and account history. A new password takes nothing away from the attacker, because he never had the old one.
What genuinely helps is aimed at the follow-up attacks. That includes requiring a hard confirmation for withdrawals in the app, refusing phone enquiries from supposed staff on principle and hanging up, and assuming with every call that cites your real account details that those details may come from this incident. The caller who knows your last transfer is no longer proof that the call is genuine.
Immediate measures: identity misuse, account security, crypto holdings
The measures fall into two groups. One concerns your identity and makes sense regardless of whether crypto is involved. The other concerns your holdings and the question of where they should sit in future.
ID data cannot be recalled
A leaked scan of an ID document stays out there. What remains is observation: check your credit file regularly for enquiries and contracts you do not recognise, and have your bank explain its rules for opening accounts and changing addresses. Where a suspicion of identity misuse arises, it belongs in a police report, because establishing when the misuse happened later decides questions of liability. Germany's financial supervisor has already warned about this pattern; we have worked through the BaFin warning on identity misuse in the crypto sector in detail.
Home address plus Bitcoin holdings: take the physical risk seriously
The most unpleasant part of this package lies outside the digital world. Whoever holds a home address, a photo from an ID document and proof of wealth has everything needed for an attack at the front door. In practice that means: no public references to crypto holdings on social networks, no deliveries of hardware accessories to your home address, and no amounts named in conversation with acquaintances. Anyone self-custodying larger sums will find the devices that allow an access lock via an additional passphrase in our hardware wallet comparison, so that a coerced access does not release the entire balance.
This caution is not a panic reaction. It matches what those affected by earlier leaks in this industry have described in hindsight, and it costs nothing but habit.

Where German Revolut customers can complain
German customers are as a rule in a contractual relationship with Revolut Bank UAB, based in Lithuania and licensed as a credit institution by the Lithuanian central bank and the European Central Bank; alongside that, the company runs a German branch. For data protection, the provider's own privacy notice names the Lithuanian data protection authority as the lead supervisory authority. Check the details in your own contract documents, because the responsible entity can differ depending on the product and the date you signed up.
This order makes sense: first the Article 15 request to the company, then the complaint to a data protection authority once the reply has arrived or the deadline has passed. A complaint to the data protection authority responsible for where you live remains open to you under the General Data Protection Regulation; in cross-border cases it passes the matter to the lead authority. Without the prior correspondence, the complaint lacks its foundation.
Regulated crypto exchanges comparedHow to reorganise your crypto holdings after a data breach
A data incident at a provider is a good occasion to review how your holdings are split, and to do it without haste. The decisive question is less which provider counts as the safest. The more useful thought is how much wealth needs to sit with any single provider at all. A trading account needs the amount that is actually being traded. Everything beyond that is a decision that could equally go the other way.
Self-custody means holding the private keys to your own coins yourself instead of entrusting them to a provider. That shifts the risk, it does not remove it: anyone self-custodying carries the risk of loss alone and needs a backup plan for the recovery phrase that survives a house fire and a house move. For many investors a split is the sensible middle path, with a small part kept ready to trade at the provider and the rest moving into self-custody.
The order matters here: the backup plan first, then the move. Anyone shifting balances in the agitation after bad news makes the most expensive mistakes of the year in that particular week.
What this case shows about KYC data at crypto providers and neobanks
KYC stands for "know your customer" and denotes the legally mandated identity check that banks and crypto service providers have to carry out before opening an account. That check is not negotiable, and at every regulated provider it creates a record made up of an ID photo, a selfie, an address and account movements. The Revolut case shows that the attack surface of this record is not made only of servers, but also of the procedures a company uses to answer requests for information.
A practical question for choosing a provider follows from that: how does the house handle official requests for information, does it publish figures on them, and how quickly does it inform those affected? Anyone looking for a new trading venue will find the providers licensed under the European supervisory framework in our overview of regulated crypto exchanges. A licence is not a promise of protection against this line of attack, but the assurance that a supervisor is responsible and reporting duties apply.
The incident joins a chain that has hit European crypto investors several times this year. The type of article is always the same because the questions are the same; our write-up on the Trezor data breach and how to check whether you were affected transfers step by step to this case.
Frequently asked questions about the Revolut data breach
Is my money at Revolut now at risk?
According to the company, systems and customer funds are unaffected by the incident, and none of the available sources contradicts that. The event is a release of documents to an unauthorised party, not access to accounts. The risk lies in what is attempted with those documents afterwards.
Do I have to change my Bitcoin addresses?
For the history already disclosed, changing addresses achieves nothing, because the past sits immutably in the chain. For future incoming payments it is still sensible to use new addresses and not to hold balances permanently on addresses that can be tied directly to a withdrawal from a provider account.
What about the claim of millions of Revolut records from the summer?
That is a different matter. The claim about a large-scale data set that surfaced on the darknet in July 2026 has no documented connection to the September request for information. Mixing the two is misleading, because the categories of data involved and the route of attack differ.
How do I know an email really comes from Revolut?
Reliably, not from the email alone. Open the app and check whether the same message is sitting in your inbox there. That rule carries more weight after this case than it did before, because a passed domain authentication simply does not prove authorisation.
Revolut data breach: what to take away
- Establish whether you are affected, do not estimate. Check in the Revolut app whether a notification is waiting, and independently of that file a subject access request under Article 15 GDPR with an explicit question about the recipients of your data. Anyone who wants to switch provider afterwards can shortlist candidates through the overview of regulated crypto exchanges.
- Decouple your holdings from your identity record. Decide what amount has to stay ready to trade at the provider, and move the rest into self-custody, with the backup plan in place before the move. The device selection including the passphrase function is in the hardware wallet comparison.
- Plan for the second wave. Expect calls and messages in the coming weeks that know your real account details, and treat every approach as unconfirmed until you have seen it in the app yourself. If you need a software solution for the part kept ready to trade, the software wallet comparison helps with the choice.
(As of September 12, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Sources: CoinDesk on the data categories involved and Revolut's statement to BeInCrypto.
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Revolut Data Breach: Your Files Are Public, and Here Is What You Can Do
- Bitcoin Tax Audit: What Proof Austria Requires
- Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
- Here’s why you should skip Facebook’s Crypto: Instagram Data Breach
- Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 15, 2026 3:53 PM

Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
August 14, 2026 6:18 PM

Bitcoin From a Foreign Exchange to Austria: Which Tax Data You Need
Transferring Bitcoin from a foreign exchange to an Austrian platform: which tax data can be missing for the withholding tax. And what investors need to watch out for.
February 26, 2018 5:26 AM

Man Who Bought 2 Pizzas for 10,000 BTC Does It Again
…this time, in a slightly different context. Eight years ago, Laszlo Hanyecz completed the first ever Bitcoin transaction for a physical good. Armed with 10,000 BTC – an astronomical sum in today’s conversion rate – he purchased two pizzas. Today, […]
August 21, 2026 1:33 PM

Bitcoin With No Cost Basis: How Austria Taxes the Sale
Bitcoin purchase price no longer provable? How Austria works out the capital gains tax, when a flat-rate cost basis applies and what investors can do.
June 7, 2026 11:00 AM

How to Buy Bitcoin with No KYC in 2026: 3 Ways to Do It
Protect your data and maintain privacy. Here are the three most secure ways to buy Bitcoin without identity verification (KYC) in 2026.
September 1, 2026 1:25 PM

Bitcoin Tax Report Wrong: What Austrian Investors Can Do
Errors in a Bitcoin tax report are not unusual. This is the data Austrian investors should check, and how a wrong capital gains tax deduction is put right.
April 28, 2026 8:36 AM

Kevin Warsh for Fed Chair: Could the First "Bitcoin-Friendly" Chair End the Crypto Crashes?
Kevin Warsh’s nomination for Fed Chair marks a shift toward pro-crypto leadership. Can he break the historical trend of Bitcoin crashes during Fed transitions?
June 24, 2024 10:37 AM

Bitcoin Price Prediction: Can BTC Price Fall Below 50K?
The profitability of Bitcoin futures cash-and-carry trades has plummeted amid a significant crypto market selloff. What are the reasons behind the decline and what can traders expect next?
September 3, 2026 10:21 AM

Bitcoin Lost in a Wallet Hack: What Tax Applies in Austria?
Bitcoin lost to hackers? In Austria, the theft of privately held coins generally does not create a capital loss you can use for tax. Only a later payout can change that.
August 16, 2026 9:05 AM

Crypto Weekly Recap: Bitcoin Slips Below $63,000 as CPI Relief Never Arrives
Bitcoin sits near $62,990 and down 2.7% on the week, ETF flows turned negative and XRP broke $1. Your Sunday crypto recap.
May 28, 2026 1:02 PM

Trump Attempts to Salvage Crypto with Bullish Promises, But Crypto Crashes Hard Anyway
Donald Trump made a major push to salvage crypto market sentiment by promising he will "never let crypto down," but Bitcoin and major altcoins crashed anyway.
May 13, 2026 6:52 PM

Why Did Bitcoin Price Crash below 80k Today?
The crypto market is in turmoil as Bitcoin and Ethereum lose critical support levels. What triggered the sudden price collapse?
March 21, 2026 9:14 AM

Why is Crypto Crashing Today? 3 Reasons Behind the Bitcoin Crash
Bitcoin and altcoins are facing a sharp sell-off today. From Middle East tensions to hot PPI data, here is why the crypto market is crashing.
January 14, 2026 2:47 PM

Crypto Markets on Edge on 14 January 2026: US PPI Surprise Ahead of the Tariff Ruling
Hot US producer prices and a pending Supreme Court tariff ruling kept crypto on edge on 14 January 2026. The ruling came on 20 February, and the Fed later raised rates.
October 26, 2020 6:56 PM

Whale Moves Over 88,000 Bitcoin In One Single Transaction ($1.15 Billion)
We just noticed a massive Bitcoin transaction of 88,857 BTC, worth around $1.15 billion at current prices. The transaction was split in two, 43,185 to one and 45,671 to the second address. Both addresses seem to be new and […]
September 1, 2024 1:30 PM

Bitcoin Price Prediction: How Will September Unfold For BTC Price?
Bitcoin price is facing significant market volatility, as it hovers around $58,000. What are the key indicators and on-chain data shaping the future of BTC Price, and how will September unfold?
September 17, 2026 7:12 PM

Gifting Bitcoin to Children: Allowance, Holding Period and the Tax Office Report
Transferring Bitcoin to your child hands over your holding period and your entry price along with the coins. This guide sets out what really applies in Germany on the allowance, the reporting deadline, representation and custody.
August 14, 2026 6:23 AM

Bitcoin Savings Plan and Tax: How the Holding Period, FIFO and the Exemption Limit Interact on Monthly Buys
Every savings plan instalment is a separate acquisition for tax purposes, with a holding period of its own. How the exemption limit, the order of disposal and record-keeping duties interact on monthly Bitcoin buys, with the sources from the statute and the Ministry of Finance circular.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
November 19, 2018 12:11 PM

Brazilian Crypto Investment Platform Atlas Quantum Hacked, Data Of 264,000 Users Leaked
Atlas Quantum, Brazilian crypto investment platform has been hacked and the data of more than 264,000 of its customers has been leaked.
April 25, 2026 9:55 AM

France Crypto Kidnappings Crisis: Pavel Durov Blasts Data Leaks and New Surveillance Laws
Pavel Durov exposes a surge in crypto-related kidnappings in France, blaming tax data leaks and warning against new social media surveillance laws.
January 10, 2026 10:20 AM

Crypto Markets Reacted to Weak US Jobs Data on 9 January 2026: What Came Next
On 9 January 2026 US payrolls rose by only 50,000 while unemployment fell to 4.4%. Crypto hoped for rate cuts. The Fed did not cut in 2026 and raised rates in September instead.
September 29, 2026 1:15 AM

BaFin warns over nova-c-solutions.com: What is behind a genuine registration number
The BaFin has warned about a website offering crypto-asset services without authorisation and speaks of a presumed identity theft at the expense of a real US company. The case shows why the advice to look a provider up in the register does not carry on its own.
September 16, 2026 7:12 PM

Borrowing Against Bitcoin Instead of Selling: When German Tax Still Applies
Posting Bitcoin as collateral for a loan is not a sale in Germany, because section 39 of the Fiscal Code keeps the coins attributed to you for tax purposes. Tax arises only when the collateral is liquidated, and then the one thing that decides the bill is how long you held the coins beforehand.
August 24, 2026 10:16 AM

Crypto Tax: Why You Have to Secure Your Transaction History Before the Exchange Closes Your Account
Deadlines run out at several crypto exchanges by early September, after which accounts close and holdings are sold off by force. Anyone who does not export the trading record beforehand faces the tax return with no proof of acquisition date and purchase price.
More from CryptoTicker

