Revolut data leak used a fake gov't domain
Revolut confirms KYC and Bitcoin transaction data exposed via a spoofed government domain request, with investigators flagging a wealth-targeting pattern.

Revolut has confirmed that customer KYC records and Bitcoin transaction data were exposed after attackers used a spoofed government domain to request account information. The company says it responded to what looked like a legitimate law enforcement inquiry, only to find the requester wasn't who they claimed to be.
The mechanism behind the breach
The attack didn't need to break Revolut's systems. It needed a domain that looked official enough to pass a compliance check, and a data request written the way regulators actually write them.
That's a process failure, not a technical one. Exchanges and neobanks build entire teams around responding fast to law enforcement, and speed is exactly what attackers exploited here.
What the numbers show
Full scope numbers from Revolut itself remain limited, but the surrounding facts point to a targeted operation rather than a scattershot phishing run.
- Onchain investigator ZachXBT flagged the incident and speculated it may have targeted high-net-worth users, per The Block.
- The exposed data set includes both KYC identity records and Bitcoin transaction history, a combination that maps wallets to real names.
- The request came through a domain designed to impersonate a government agency, not a generic spoofed email.
That pairing of identity plus onchain activity is the valuable part. Transaction data alone is pseudonymous. KYC alone is just a name and address. Together, they let someone build a target list.
The read on who this really hits
Most coverage of a breach like this will frame it as a customer-privacy story: another exchange failed to protect user data. The details here point somewhere more specific.
Attackers who fake a government domain to pull KYC-plus-transaction data aren't running a mass phishing campaign. They're doing reconnaissance.
ZachXBT's read that high-net-worth users were the target fits the method. A wide breach dumps millions of records for resale. A narrow, domain-spoofed request against a live compliance process looks built to identify specific wallets holding real balances, then match them to real names and addresses.
That's the setup for targeted extortion or physical targeting, not credential-stuffing at scale. The KYC-to-wallet link is precisely the bridge that most crypto operational security assumes doesn't exist.
Revolut's compliance pipeline is the same pipeline every regulated custodian runs. Law enforcement requests get expedited because refusing them carries legal risk. That urgency is the exploit surface, and it isn't unique to Revolut.
What would confirm or kill this
The targeting theory is testable against what surfaces next, both from Revolut's own disclosure and from onchain behavior tied to affected accounts.
- Revolut names a confirmed count of affected accounts and whether they skew toward larger balances or KYC tiers.
- Onchain trackers flag unusual movement, consolidation, or hacks tied to wallets linked to exposed users in the weeks after disclosure.
- Other custodians report similar spoofed-domain requests, showing whether this is a single incident or a method now in circulation.
