Customer identity verification data and Bitcoin ($BTC) transaction records held at Revolut were accessed through a fraudulent request that impersonated a government domain, the company confirmed. Onchain investigator ZachXBT speculated the incident targeted high-net-worth users.
The breach covered two distinct categories of data. KYC files contain the identification documents customers submit during onboarding. Bitcoin transaction records add the behavioral layer: the pattern, counterparties, and timing of on-chain activity. Together, they link a verified identity to its financial footprint on the network without requiring any direct access to the blockchain.
The attack vector relied on a fake government domain. Compliance frameworks at financial institutions generally treat requests from regulatory or law enforcement addresses as authoritative, which means a convincingly spoofed government source can move sensitive data outside the scrutiny applied to ordinary inquiries.
ZachXBT, who tracks illicit fund flows on public blockchains, characterized the exposure as potentially deliberate. His read: the fraudulent request may have been engineered to surface records for high-net-worth accounts specifically, rather than to harvest data broadly.
That framing shifts the incident from opportunistic breach toward targeted reconnaissance. KYC paired with $BTC transaction history hands an attacker a profile that the public blockchain alone cannot supply.
Revolut has not disclosed how many users were affected or when the fraudulent request was submitted.