Revolut Data Breach: Your Files Are Public, and Here Is What You Can Do
Since September 14, the ID copies, KYC selfies and account statements stolen from Revolut have been published. What a password change no longer achieves, which rights the GDPR gives you, and why your Bitcoin history is the most sensitive part of the package.

Table of Contents
Table of Contents
When a copy of your ID document, your verification selfie and your complete Bitcoin transaction history all sit in one package in the hands of strangers, a new password achieves almost nothing. That has been the position of the Revolut customers who received a breach notification since September 14, 2026: the stolen documents have been published since the early hours of that day. Four things matter now. Establish in writing how far your own exposure goes. Close the routes through which a copy of an ID document turns into money. Take the link between your home address and your crypto holdings seriously. And enforce your rights against the bank while the deadlines are still running.
This piece builds on our first assessment. Whether you are among the affected customers at all, and what role your Bitcoin history plays in the incident, is covered in Revolut data breach: am I affected, and what about my Bitcoin history? from September 12. This article deals with the stage after that: the details are out, and that changes the question of what to do.
Revolut data breach: what to do now that the files are being published
Until the weekend, the security incident was an outflow of customer data. Since the night of September 14, Cointelegraph has reported that copies of identity documents and verification selfies belonging to Revolut customers have surfaced online. According to the outlet, the attackers are announcing on Telegram that they will release further data sets every day until Revolut pays. One affected customer confirmed to Cointelegraph that the published details match the documents held on file at Revolut, and that the neobank wrote to him on Friday.
One point matters for the assessment: the existence of a ransom demand is the attackers' own account, relayed by a trade publication citing a Telegram post. Revolut itself does not confirm any such demand. A specific Bitcoin sum is also circulating on aggregator sites as the alleged ransom. There is no solid evidence for that figure, which is why it does not appear as fact in this article.
The practical difference from last week is considerable nonetheless. As long as a data set sits only with one criminal group, it needs a buyer before it can be used against you. Once it is publicly retrievable, that intermediate step falls away, and the number of possible fraudsters grows from one group to anyone who finds the file.
Which data fields Revolut lists in its customer email
The trade publication BleepingComputer quotes the notification Revolut sent to affected customers verbatim. According to that text, the incident covers the full name, date of birth, occupation, postal address, email address and telephone number. On top of that come copies of an identity card or driving licence, the selfies from the identity check, account statements including the IBAN, withdrawal records and the complete transaction history including Bitcoin transactions.
Revolut speaks of a limited number of affected users but gives no figure. According to the company, neither its own systems were compromised nor were customer funds touched. Both statements are plausible and both change little about your position. The damage from this incident does not hit your balance. It sits in the paperwork.
The outflow was triggered, on the company's account, by a forged request that looked like an information request from a government authority. Such emergency data requests are an established procedure: where there is imminent danger, authorities demand subscriber data without waiting for the regular judicial route. The forged request came from a genuine government domain and passed the technical sender authentication checks. That is exactly where the weak point sat. A technically correct signed email proves that the domain is genuine. It proves nothing about whether the request behind it is lawful.
Why a leaked ID scan is not a case for Germany's 116 116 blocking hotline
Many affected people reach first for the same reflex: have the ID card blocked. In Germany that runs through the free blocking hotline 116 116, and in this case it is the wrong step. What gets blocked there is the online ID function, the eID on the chip of your identity card. That function requires the physical card plus the six-digit PIN. A scanned copy cannot trigger it.
Your ID card is still in your drawer, and the eID is not the way in. The risk sits with every provider that accepts an image file of an ID document as proof: credit brokers, mobile operators, mail-order retailers offering purchase on account, and some trading platforms with weak checks. Blocking the eID would have no effect there and would only cost you the use of digital government services.
A different set of measures does work. File a criminal complaint with the police, online through the digital police station of your federal state; the case number is later your evidence towards any creditor chasing a claim taken out in your name. Request a free copy of your data from the major credit reference agencies and check whether contracts appear there that you never signed. And set yourself a reminder, because identity abuse using copies of ID documents often only shows up months later. The German Federal Office for Information Security sets out the individual steps for victims of data breaches and doxing in detail.

ID scan and KYC selfie together: the problem with the liveness check
An ID scan on its own is a known risk. The combination of an ID copy and the selfie from the same identity check is a different order of magnitude, because that pair is the standard proof used to open an account. Many providers require a photo of the document and an image of the face, and some match the two automatically.
The safeguard against this is called a liveness check, and it is meant to establish whether a living person is sitting in front of the camera or a photographed image. Good procedures demand head movements, changing light patterns or depth capture; weak ones make do with an uploaded still image. Wherever only a still image is required, a leaked verification selfie is immediately usable.
That produces a concrete task for crypto users: look up which trading venues hold your ID document, and close the accounts you no longer use. Every dormant registration is one copy of your paperwork less in circulation. Where you stay active, switch on two-factor authentication through an authenticator app or a security key rather than by SMS, because the phone number is part of this breach. Which platforms in Germany operate under supervision at all, and how to check that, is covered in our overview of regulated crypto exchanges.
Bitcoin transaction history in someone else's hands: what address clustering makes possible
The part of the package that separates this incident from an ordinary bank data breach is the transaction history. Bitcoin is a public database: every transfer sits in the chain for anyone to inspect. What the chain lacks is the link between an address and a person. An account statement with withdrawal records delivers exactly that link, free of charge.
Address clustering is the name of the technique that derives a whole bundle of addresses from a single known one: when several addresses appear together as the inputs of a transaction, they very probably belong to the same wallet. Anyone who knows one of your withdrawal addresses can work outwards from there and often arrives at an estimate of your total holdings. The technique is neither new nor illegal; analytics firms and investigators have worked with it for years. What is new is that the starting point for it is now lying around in public.
The obvious question is whether you should change your addresses. For future payments yes; for the past it cannot be done. A transaction once written into the chain cannot be retrieved. In practice that means: use fresh addresses for new incoming payments, avoid merging old and new holdings in a single transaction, and for larger amounts do not pay in and withdraw through the same platform.
Home address plus crypto holdings: putting the physical risk in perspective
The on-chain investigator ZachXBT reads the incident as one where the breach looks small but appears deliberately aimed at wealthy users. That is his assessment and not an established fact, but it deserves attention because it fits the structure of the data: postal address, date of birth and occupation together with a traceable Bitcoin history produce a profile that goes beyond the usual phishing purpose.
We have described this pattern twice already in our coverage, most recently in the Trezor data breach in September, in which names, phone numbers and home addresses of hardware wallet buyers were exposed. The lesson from it applies here just the same. Do not talk about amounts in the neighbourhood or on the phone. Treat parcel notifications and supposed callbacks from the bank's service team with suspicion, even when your name, your date of birth and your most recent debit are quoted correctly. Those details are precisely what is in the package, and a caller who knows them has proved nothing by doing so.
In concrete terms that also means setting yourself a callback rule at your bank and at your trading venues. No process that begins on the phone is completed on the phone. Hang up and dial the number from the app or from your account statement. That single habit strips most of the value out of what a cybercriminal can do with your documents.
What to do if your Revolut account has been hacked
One important distinction first: no account was taken over in this incident. According to the company, documents were handed out; login credentials were not stolen. If your account really is being controlled by someone else, a different procedure applies, and it begins with blocking.
Block the card in the app and, if you no longer have access, through the bank's customer service. Report every unauthorised debit without delay; under payment services law you are as a rule reimbursed for an unauthorised payment as long as you have not acted with gross negligence, and the bank has to prove the authorisation. Then change the password of your email inbox, because it is the master key to every other login. Finally, check the connected devices and sessions in every account that uses the same email address, and throw out any session you do not recognise.
Record every one of these steps in writing, with date and time. Anyone who later claims damages or disputes a demand needs that record.

The coming weeks: a review plan with fixed dates
Identity abuse after a security breach rarely starts immediately. Weeks, sometimes months, pass between the outflow and the first attack made in your name, because the data sets first have to be sorted, merged and passed on. A review plan with fixed dates therefore works better than a single frantic afternoon.
This week: send off the Article 15 access request, file the criminal complaint, and switch two-factor authentication everywhere to an app or a security key. Note down as well which postal addresses and which phone number were held on file at the neobank. Anyone who later receives a message quoting exactly those details will recognise at once which source the sender is drawing on.
In four weeks: request a copy of your data from the credit reference agencies and check it for entries you do not recognise; every credit enquiry you never made is a warning sign. In the same pass, go through the login logs of your most important accounts and report every access from a region you were not in.
After three months and after six: the same again. As long as your passport is in circulation as an image file, it keeps its value for fraudsters until its expiry date.
One expectation is worth dropping along the way. Checking services that promise to track down your data on the dark web are in reality searching a database of collections that are already known. Such systems give usable pointers about older incidents and still offer you no all-clear about a fresh one, because all they can show is what has already been traded in public. Rely on the information from your own Article 15 response rather than on a green light.
Your rights under the GDPR: access under Article 15, complaint under Article 77
The notification Revolut sent out is an obligation under Article 34 of the General Data Protection Regulation: where a breach is likely to result in a high risk to those affected, the company has to inform them without delay. That email, however, only tells you that you are affected, not to what extent.
You obtain the extent through Article 15 GDPR, the right of access. Ask in writing for a copy of the data processed about you and, expressly, for a statement of which categories were disclosed to which recipients. The deadline is one month and can be extended by two months if the company gives reasons. That response is the only solid evidence of what was actually handed out in your case, and it is free.
If no answer arrives, or an unusable one, Article 77 GDPR applies: a complaint to a supervisory authority, expressly including the authority where you habitually reside. For German customers that is the data protection authority of your federal state. The fact that Revolut Bank UAB is based in Lithuania and that the authority there is competent under the lead supervisory authority procedure changes nothing; your state authority accepts the complaint and passes it on. The German branch in Berlin is additionally supervised by BaFin, which is not, however, responsible for data protection.
On damages under Article 82 GDPR, the position in Germany has been clearer since the Federal Court of Justice ruling of November 18, 2024 (case reference VI ZR 10/24): the mere loss of control over your own data can amount to compensable non-material damage, without any abuse having to be proven. You do have to set out that loss of control yourself. The amount depends on the individual case, and the sums awarded so far sit in the low hundreds.
Is Revolut monitored by the tax office? What applies under DAC8 since 2026
This question comes up after every incident of this kind, and the answer has nothing to do with the breach. Nobody is being monitored. What has been reported automatically since January 1, 2026 is something else: Germany's crypto asset tax transparency act transposes the European DAC8 directive into national law and obliges crypto asset service providers to record and transmit tax-relevant customer and transaction data. The first reporting period is the 2026 calendar year, and the data goes to the Federal Central Tax Office by July 31, 2027.
For you that has two consequences. The details crypto providers hold about you will grow rather than shrink, and keeping clean records of your own is no longer optional. A reported sum is also not your profit: what gets reported are proceeds and transactions, while the acquisition costs are known only to your own documentation. Anyone who does not keep it is later negotiating against a figure they have nothing to set against it. A portfolio tracker with tax reporting solves exactly that problem.
Extortion, ransom, millions of records: what is proven and what is not
Several narratives are running alongside each other around this security incident, and the differences matter for your own judgement.
Proven is the notification to those affected together with the list of data fields, because Revolut sent it out itself and a trade publication reproduces it verbatim. It is also proven that copies of identity documents and verification selfies have surfaced publicly; one affected customer confirmed the match to Cointelegraph.
Claimed is the extortion. The threat of daily publication comes from a Telegram post by the alleged perpetrators. A company being extorted rarely confirms it, and Revolut does not do so here. Anyone mentioning the demand should say who is making it.
Disputed is an older matter that is resurfacing: over the summer, a database allegedly holding tens of millions of Revolut records was offered on the dark web in the relevant forums. German media reported on it, Revolut denied its authenticity and pointed to material compiled from other sources. That episode has to be kept separate from the current one. Anyone who throws the two together arrives at a number of affected customers that nobody has evidenced.
For handling the days ahead, that means: expect phishing that looks very convincing. Whoever knows your name, date of birth, IBAN and most recent transactions no longer writes a clumsy spam email. The only reliable test remains the channel, not the content. A genuine bank never asks you by email or telephone to move funds to a security account, to enter a recovery phrase or to install remote access software. At the slightest doubt, go through the app you installed yourself.
Self-custody as a consequence: when a hardware wallet shortens the data trail
This case exposes a property of custody arrangements that stays invisible in everyday use: anyone holding crypto assets with a provider leaves behind a complete identity file there alongside the balance. That file is the actual subject of the incident. A hardware wallet does not change all of it, but it does shorten the trail at one decisive point: the balance no longer sits with a third party afterwards, and that third party's failure or data breach no longer separates you from your coins.
It is worth staying honest all the same. The purchase itself generates data again, as the Trezor breach mentioned above shows; so never order to an address that is also where you live, if you can avoid it, and buy only from the manufacturer or authorised resellers. The transfer from an exchange to your own wallet is also visible in the chain and can be linked to your account statements. And responsibility for the recovery phrase then lies entirely with you. Self-custody is a shift of risk, not its abolition.
For whatever is meant to stay on a platform, selection comes down to supervision and custody practice. Ask about segregated custody, about who the custodian is, and about the licence under which that custodian operates.
Revolut data breach: what to take away
- Establish your exposure in writing. Request the Article 15 GDPR access response today and note the date you sent it. Without that list you will later be arguing over assumptions. In parallel, check which trading venues hold a copy of your ID document and close the accounts you do not use; our overview of regulated crypto exchanges shows what matters with the ones you keep.
- Separate identity and holdings. Use fresh receiving addresses, do not merge old and new holdings in a single transaction, and move the part you hold long term into your own custody. Our comparison of hardware wallets names the devices along with their weaknesses.
- Get your records in order before the first DAC8 report goes out. Complete acquisition data is your only counter-argument against a reported sum from the 2026 reporting period onwards. A tax and portfolio tracker takes over the collecting.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Revolut Data Breach: Am I Affected, and What About My Bitcoin History?
- Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
- Bitcoin From a Foreign Exchange to Austria: Which Tax Data You Need
- Man Who Bought 2 Pizzas for 10,000 BTC Does It Again
- How to Buy Bitcoin with No KYC in 2026: 3 Ways to Do It































