Revolut Breach Shows How KYC Data Became a Honeypot for Scammers

Monday, 14/09/2026 | 14:55 GMT by Tanya Chepkova
  • Financial firms must retain identity and transaction records that criminals can use to identify and approach valuable targets.
  • Two separate Revolut cases show how the risk can emerge without a conventional breach of banking systems.
France Revolut

Financial institutions ask customers for passports, facial images, addresses and information about their money to meet regulatory requirements.

Stored together, however, the same records can become a ready-made targeting file for criminals—and obtaining it may not require breaking into a bank’s systems.

London's trading industry is coming home!

What Happened to Revolut

The latest data security incident exposed the risk, when Revolut provided sensitive customer information in response to fraudulent requests sent from an email account within a legitimate government agency domain.

The incident was first circulated by on-chain investigator ZachXBT, who published screenshots of customer notices sent by Revolut.

Revolut told Finance Magnates that it had identified “a sophisticated external impersonation scam” in which an unauthorised third party used an email address within a legitimate government agency domain to submit fraudulent information requests.

“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” a Revolut spokesperson said. “Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support.”

The statement did not identify the government agency, affected markets or number of customers. It also did not explain what verification was conducted before the requests were fulfilled or what changes had subsequently been made to the approval process.

Why Financial Firms Must Keep Sensitive Records

Banks, brokers, and crypto platforms don't accumulate customer records at will. They have to do it to comply with anti-money laundering requirements.

Revolut’s privacy notice says the company collects copies of identification documents, customer photographs or videos and facial scan data used for identity verification. It also processes account, transaction and, where relevant, external crypto-wallet information.

The notice says KYC, banking and anti-money laundering rules require Revolut to retain certain customer information. In the UK, the company generally keeps personal data for up to seven years after the business relationship ends, with longer retention possible for legal reasons. Thus, closing an account does not necessarily remove the underlying identity file.

The regulatory need to retain records does not, however, determine how broadly they should be accessible or whether identity and transaction data should be assembled into a single disclosure.

Revolut says it holds its records on secure systems and that access management controls restrict them to authorised employees. Its public policies do not explain how it authenticates government requests or approves the scope of each disclosure.

How One Dataset creates Multiple Routes of Attack

Once KYC records leave a financial institution, the same dataset can be used against both the company that collected it and the customers it describes.

Separately, online posts have alleged that customer files are being published and that a demand for 10,000 Bitcoin was made. Finance Magnates could not authenticate the files, verify the demand or establish that the group was connected to the fraudulent requests. Revolut has not publicly confirmed the claims.

However, if genuine, the incident would show how exposed KYC records can create pressure on the institution itself, not only on the customers whose data was disclosed. Regulatory scrutiny, reputational damage and customer complaints can become part of the leverage.

The records can also be monetised directly against individual customers. Identity documents and verification photographs can support impersonation, while contact details and transaction histories let scammers tailor their approach with information a generic phishing message would not include.

As Finance Magnates previously reported, organised crypto criminals have used hacked and purchased databases to identify valuable targets before callers approached them with customised stories. The objective was to establish who controlled the assets and persuade or coerce that person into transferring them.

The February allegations involving a former Revolut employee showed another version of customer-level pressure. A cryptocurrency trader alleged that the former employee threatened to disclose his private information and contacted his relatives.

Revolut referred the matter to law enforcement and maintained that its systems and data protection protocols operated as intended. No evidence connects that case to the latest incident.

Stolen KYC data can therefore serve as both leverage against an institution and inventory for subsequent fraud against its clients. Paying an extortion demand, even if one has been made, would not eliminate the second risk once the records had been copied.

Financial institutions ask customers for passports, facial images, addresses and information about their money to meet regulatory requirements.

Stored together, however, the same records can become a ready-made targeting file for criminals—and obtaining it may not require breaking into a bank’s systems.

London's trading industry is coming home!

What Happened to Revolut

The latest data security incident exposed the risk, when Revolut provided sensitive customer information in response to fraudulent requests sent from an email account within a legitimate government agency domain.

The incident was first circulated by on-chain investigator ZachXBT, who published screenshots of customer notices sent by Revolut.

Revolut told Finance Magnates that it had identified “a sophisticated external impersonation scam” in which an unauthorised third party used an email address within a legitimate government agency domain to submit fraudulent information requests.

“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” a Revolut spokesperson said. “Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support.”

The statement did not identify the government agency, affected markets or number of customers. It also did not explain what verification was conducted before the requests were fulfilled or what changes had subsequently been made to the approval process.

Why Financial Firms Must Keep Sensitive Records

Banks, brokers, and crypto platforms don't accumulate customer records at will. They have to do it to comply with anti-money laundering requirements.

Revolut’s privacy notice says the company collects copies of identification documents, customer photographs or videos and facial scan data used for identity verification. It also processes account, transaction and, where relevant, external crypto-wallet information.

The notice says KYC, banking and anti-money laundering rules require Revolut to retain certain customer information. In the UK, the company generally keeps personal data for up to seven years after the business relationship ends, with longer retention possible for legal reasons. Thus, closing an account does not necessarily remove the underlying identity file.

The regulatory need to retain records does not, however, determine how broadly they should be accessible or whether identity and transaction data should be assembled into a single disclosure.

Revolut says it holds its records on secure systems and that access management controls restrict them to authorised employees. Its public policies do not explain how it authenticates government requests or approves the scope of each disclosure.

How One Dataset creates Multiple Routes of Attack

Once KYC records leave a financial institution, the same dataset can be used against both the company that collected it and the customers it describes.

Separately, online posts have alleged that customer files are being published and that a demand for 10,000 Bitcoin was made. Finance Magnates could not authenticate the files, verify the demand or establish that the group was connected to the fraudulent requests. Revolut has not publicly confirmed the claims.

However, if genuine, the incident would show how exposed KYC records can create pressure on the institution itself, not only on the customers whose data was disclosed. Regulatory scrutiny, reputational damage and customer complaints can become part of the leverage.

The records can also be monetised directly against individual customers. Identity documents and verification photographs can support impersonation, while contact details and transaction histories let scammers tailor their approach with information a generic phishing message would not include.

As Finance Magnates previously reported, organised crypto criminals have used hacked and purchased databases to identify valuable targets before callers approached them with customised stories. The objective was to establish who controlled the assets and persuade or coerce that person into transferring them.

The February allegations involving a former Revolut employee showed another version of customer-level pressure. A cryptocurrency trader alleged that the former employee threatened to disclose his private information and contacted his relatives.

Revolut referred the matter to law enforcement and maintained that its systems and data protection protocols operated as intended. No evidence connects that case to the latest incident.

Stolen KYC data can therefore serve as both leverage against an institution and inventory for subsequent fraud against its clients. Paying an extortion demand, even if one has been made, would not eliminate the second risk once the records had been copied.

About the Author: Tanya Chepkova
Tanya Chepkova
  • 458 Articles
  • 3 Followers
About the Author: Tanya Chepkova
Tanya Chepkova is a News Editor at Finance Magnates with more than 16 years of experience in financial journalism, covering forex, crypto, and digital asset markets. Her work spans daily industry reporting and data-driven, long-form explainers focused on market structure, trading models, and regulatory shifts. Before joining Finance Magnates, she led the editorial team of a cryptocurrency-focused media outlet for six years. Her reporting combines analytical depth with clear storytelling, with particular attention to how structural changes in trading, stablecoin infrastructure, and emerging products such as prediction markets reshape the broader financial ecosystem. She covers global developments and provides additional insight into CIS markets. Areas of Coverage: Crypto and digital asset markets Prediction markets Stablecoins and cross-border payments Industry analysis and long-form explainers
  • 458 Articles
  • 3 Followers

More from the Author

FinTech

!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|} !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}