A Revolut data breach has exposed an unsettling overlap between financial privacy and the identity records banks keep on their customers.
This week, a fraudulent email posing as a government request slipped through Revolut’s security checks, prompting the digital bank to hand over sensitive customer information before discovering that the request was fake.
The exposed material reportedly went far beyond basic account details. It included passports or driving licences, identity-verification selfies, names, dates of birth, occupations, home addresses, email addresses, phone numbers and IBANs.
For some customers, the files also contained account statements, withdrawal records and complete transaction histories, including Bitcoin activity.
Revolut said customer funds were not affected. After separately contacting the purported government agency and learning that the request was fraudulent, the company blocked the source, notified affected users and regulators, and began addressing the incident.
The bank has not disclosed how many customers were caught up in the breach and did not immediately respond to a CoinDesk request for comment.
Why the Revolut data breach makes Bitcoin privacy feel personal
The most uncomfortable part of the incident is not necessarily the theft of money. It is the possibility of stitching a real identity to financial behavior.
Bitcoin transactions themselves are recorded publicly on the blockchain. A wallet address does not automatically reveal a person’s name, home or occupation, however. That connection often exists elsewhere — inside the databases of exchanges, banks and other financial intermediaries.
Once those records are combined, the picture changes. A transaction history that looks abstract onchain can become a detailed record attached to a real individual, complete with an address and identity documents.
That creates a particularly sensitive target for anyone looking to identify people with substantial Bitcoin holdings.
Onchain investigator ZachXBT said in a Telegram broadcast that the incident appeared relatively limited in scope and may have involved high-net-worth customers.
The episode also arrives at an awkward moment for digital security. Generative AI has made convincing documents, identities and official-looking messages easier to produce, while financial companies continue to accumulate more information about their customers.
The problem, in other words, is not only whether a company can keep a database secure. It is whether that database needs to contain so much information in the first place — and how much of it should have to change hands whenever someone asks for proof of identity.
That is where privacy-preserving technology becomes more than an abstract cryptography concept.
Zero-knowledge systems, for example, can let someone prove that they completed an identity check or meet a particular requirement without necessarily exposing the underlying passport, address or other personal records.
The network can make transactions publicly visible while leaving identity data offchain. But when an intermediary links those two worlds, a supposedly separate financial trail can become a map of a person’s life.
As impersonation gets easier, the harder security question may no longer be how perfectly institutions protect sensitive data. It may be why they are collecting, storing and disclosing so much of it at all.
