The digital banking and cryptocurrency platform Revolut has reportedly fallen victim to a sophisticated social engineering attack, resulting in the unauthorized disclosure of sensitive information belonging to 680 individuals. According to reports from the Financial Times on September 15, 2026, the breach occurred after cybercriminals successfully impersonated government officials to solicit private records. The compromised data includes highly sensitive personal identifiers and financial details, raising significant privacy concerns for the affected fintech users.
Social Engineering and the Scope of Data Loss
The incident was initiated when an attacker gained access to a legitimate government email address. Using this credible vector, the hacker sent fraudulent requests for information to Revolut’s compliance department. Believing the requests to be official legal inquiries, the company complied by handing over comprehensive data packets.
The leaked information is reported to include:
- Identification documents and passport details.
- Full home addresses and bank account numbers.
- Verification photographs used for Know Your Customer (KYC) protocols.
- Detailed records of Bitcoin (BTC) transaction activity.
Social engineering remains one of the most potent threats to financial institutions, as it bypasses technical firewalls by exploiting human trust and administrative procedures.
Regulatory Investigation and Affected Parties
Among those confirmed to be impacted by the breach is Mark Karpelès, the former CEO of the defunct cryptocurrency exchange Mt. Gox. The attacker reportedly attempted to extort the firm, threatening to release the sensitive data publicly unless a ransom was paid. In response to the breach, the UK Information Commissioner's Office (ICO) has confirmed that it is currently investigating the matter to determine if Revolut adhered to data protection regulations.
The ICO is aware of this incident involving Revolut and is making enquiries.
While Revolut has officially stated that its core internal systems and customer funds were not compromised, the company has declined to provide a public statement regarding the exact number of individuals affected, though sources indicate the firm has already begun contacting the 680 victims.
Implications for Crypto Asset Privacy
The inclusion of Bitcoin activity in the leaked data highlights the specific risks faced by cryptocurrency investors. Unlike traditional banking, the exposure of a user's wallet activity combined with their physical address and identity documents can lead to targeted physical and digital threats. This event underscores the ongoing tension between regulatory compliance—which requires fintechs to store massive amounts of user data—and the imperative of cybersecurity to protect that information from malicious actors.
Frequently Asked Questions
Quick answers to the most common questions about this topic.