Revolut Data Breach: Immediate Steps After Identity Documents and Bitcoin History Leak Online
When copies of your ID document, verification selfie, and complete Bitcoin transaction history are bundled together in the hands of strangers, changing your password offers almost no protection. That reality confronts Revolut customers who received breach notifications starting September 14, 2026, the same day stolen documents began appearing publicly. Four priorities now demand action: establish the exact scope of your exposure in writing, close pathways that turn an ID copy into money, treat the link between your home address and crypto holdings seriously, and enforce your rights against the bank while legal deadlines remain open.
What Happened: From Data Outflow to Public Release
Until mid-September, the incident was a private data outflow. On the night of September 14, Cointelegraph reported that copies of identity documents and verification selfies belonging to Revolut customers had surfaced online. According to the outlet, the attackers announced on Telegram that they would release further data sets daily until Revolut pays a ransom. One affected customer confirmed to Cointelegraph that the published details match the documents held by Revolut and that the neobank contacted him on Friday.
Important distinction: The existence of a ransom demand comes solely from the attackers’ own Telegram post, relayed by a trade publication. Revolut does not confirm any such demand. A specific Bitcoin sum circulating on aggregator sites as the alleged ransom lacks solid evidence and is not treated as fact here.
The practical difference from the previous week is significant. While data held by a single criminal group requires a buyer before it can be weaponized, public availability removes that intermediate step, expanding the pool of potential fraudsters from one group to anyone who finds the files.
Data Fields Confirmed in Revolut’s Customer Notification
The trade publication BleepingComputer quotes the notification Revolut sent to affected customers verbatim. According to that text, the breach covers:
- Full name
- Date of birth
- Occupation
- Postal address
- Email address
- Telephone number
- Copies of an identity card or driving licence
- Selfies from the identity verification check
- Account statements including IBAN
- Withdrawal records
- Complete transaction history, including Bitcoin transactions
Revolut describes the number of affected users as limited but provides no figure. The company states its own systems were not compromised and customer funds were not touched. Both claims are plausible but do not alter the victim’s position: the damage sits in the paperwork, not the balance.
The breach originated from a forged request mimicking an emergency government data request. Such requests are a legitimate procedure where authorities demand subscriber data without judicial oversight in imminent danger scenarios. The forged request came from a genuine government domain and passed technical sender authentication checks. This highlights the vulnerability: a technically valid signed email proves domain authenticity, not the lawfulness of the request behind it.
Why Blocking Your German ID Card via 116 116 Is the Wrong Move
Many affected individuals instinctively try to block their ID card through Germany’s free hotline 116 116. In this case, that step is ineffective. The hotline blocks the online ID function (eID) on the card’s chip, which requires the physical card plus a six-digit PIN. A scanned copy cannot trigger the eID.
Your physical ID card remains in your possession, and the eID is not the attack vector. The risk lies with any provider that accepts an image file of an ID document as proof—credit brokers, mobile operators, mail-order retailers offering purchase on account, and some trading platforms with weak checks. Blocking the eID would only cost you access to digital government services without mitigating the actual threat.
Effective Identity Protection Measures
Instead, take these concrete steps:
- File a criminal complaint with the police via your federal state’s digital police station; the case number serves as evidence against any future fraudulent claims.
- Request a free copy of your data from major credit reference agencies and check for contracts you never signed.
- Set a reminder: identity abuse using copied ID documents often surfaces months later. The German Federal Office for Information Security (BSI) details further steps for data breach and doxing victims.
The Critical Combination: ID Scan Plus KYC Selfie
A leaked ID scan alone is a known risk. The combination of an ID copy and the selfie from the same identity check is a different order of magnitude because that pair is the standard proof used to open accounts. Many providers require a photo of the document and a facial image, often matched automatically.
The safeguard is a liveness check, designed to verify a living person is present rather than a static image. Strong procedures demand head movements, changing light patterns, or depth capture; weak ones accept a simple uploaded still image. Wherever only a still image is required, a leaked verification selfie becomes immediately usable.
Action for crypto users: Identify which trading venues hold your ID document and close unused accounts. Every dormant registration is one less copy of your paperwork in circulation. For active accounts, enable two-factor authentication via an authenticator app or security key—not SMS—because your phone number is part of this breach. Our overview of regulated crypto exchanges in Germany explains how to verify platform supervision.
Bitcoin Transaction History in the Wrong Hands: Address Clustering Risks
The inclusion of complete transaction history separates this incident from a typical bank data breach. Bitcoin’s blockchain is public; every transfer is visible. What the chain lacks is the link between an address and a real-world identity. An account statement with withdrawal records provides that link for free.
Address clustering derives a bundle of addresses from a single known one: when several addresses appear together as transaction inputs, they likely belong to the same wallet. Anyone with one of your withdrawal addresses can work outward and often estimate your total holdings. This technique is neither new nor illegal—analytics firms and investigators have used it for years. What is new is that the starting point for such analysis is now publicly available.
Should you change your addresses? For future payments, yes; for past transactions, it’s impossible. A transaction written to the blockchain cannot be erased. Practical steps:
- Use fresh addresses for new incoming payments.
- Avoid merging old and new holdings in a single transaction.
- For larger amounts, do not deposit and withdraw through the same platform.
Home Address Plus Crypto Holdings: Assessing Physical Risk
On-chain investigator ZachXBT assesses that the breach appears small but deliberately aimed at wealthy users. While this is his assessment and not established fact, it warrants attention because the data structure—postal address, date of birth, occupation, and traceable Bitcoin history—creates a profile extending beyond typical phishing.
This pattern mirrors the Trezor data breach in September, which exposed names, phone numbers, and home addresses of hardware wallet buyers. The lesson applies equally here:
- Do not discuss crypto amounts in your neighborhood or on the phone.
- Treat parcel notifications and supposed bank callbacks with suspicion, even when the caller quotes your name, date of birth, and recent transactions correctly—those details are in the leaked package.
Implement a callback rule at your bank and trading venues: no process initiated by phone is completed by phone. Hang up and dial the number from your app or account statement. This single habit neutralizes much of the value a cybercriminal can extract from your documents.
What to Do If Your Revolut Account Is Actually Hacked
Clarification: no account takeover occurred in this incident. Revolut states documents were disclosed; login credentials were not stolen. If your account is genuinely being controlled by someone else, a different procedure applies:
- Block the card in the app, or via customer service if you’ve lost access.
- Report every unauthorized debit immediately; under payment services law you are typically reimbursed for unauthorized payments unless you acted with gross negligence, and the bank must prove authorization.
- Change your email password—it is the master key to every other login.
- Check connected devices and sessions in all accounts using that email, and remove unrecognized sessions.
Document every step in writing with date and time. This record is essential for any future damage claims or disputes.
Review Plan with Fixed Dates: Identity Abuse Rarely Starts Immediately
Weeks or months often pass between a data outflow and the first attack in your name, as data sets are sorted, merged, and passed on. A structured review plan works better than a single frantic afternoon.
This Week
- Send the Article 15 GDPR access request.
- File the criminal complaint.
- Switch two-factor authentication everywhere to an authenticator app or security key.
- Note which postal addresses and phone numbers Revolut held on file; any future message quoting those details instantly reveals the source.
In Four Weeks
- Request data from credit reference agencies and check for unrecognized entries; every credit inquiry you didn’t initiate is a warning sign.
- Review login logs of your most important accounts and report any access from regions you weren’t in.
After Three Months and Six Months
Repeat the four-week checks. As long as your passport circulates as an image file, it retains value for fraudsters until its expiry date.
Drop this expectation: Dark web monitoring services only search databases of already-known collections. They provide pointers on older incidents but offer no all-clear for a fresh breach. Rely on your own Article 15 response, not a green light from a monitoring service.
Your GDPR Rights: Access, Complaint, and Damages
Revolut’s notification fulfills its obligation under Article 34 GDPR (high-risk breach notification). That email tells you that you are affected, not the extent. Obtain the full scope through Article 15 GDPR (Right of Access): request in writing a copy of all data processed about you and an explicit statement of which categories were disclosed to which recipients. The deadline is one month, extendable by two months with justification. This response is your only solid evidence of what was actually disclosed in your case, and it is free.
If no answer arrives or the response is unusable, Article 77 GDPR allows a complaint to a supervisory authority—including the authority where you habitually reside. For German customers, that is your state data protection authority. Revolut Bank UAB’s Lithuanian base and the lead supervisory authority procedure do not change this; your state authority accepts the complaint and forwards it. The German branch in Berlin is supervised by BaFin, which is not responsible for data protection.
Regarding Article 82 GDPR damages, the German Federal Court of Justice ruling of November 18, 2024 (case VI ZR 10/24) clarified that mere loss of control over your data can constitute compensable non-material damage without proven abuse. You must articulate that loss of control; awarded amounts so far sit in the low hundreds.
Tax Reporting Under DAC8: What Changed in 2026
Questions about tax office monitoring arise after every such incident. The answer is unrelated to the breach: no one is being monitored. Since January 1, 2026, Germany’s Crypto Asset Tax Transparency Act transposes the EU DAC8 directive, obliging crypto asset service providers to record and transmit tax-relevant customer and transaction data. The first reporting period is the 2026 calendar year, with data due to the Federal Central Tax Office by July 31, 2027.
Two consequences for you:
- Details held by crypto providers will grow, not shrink; keeping clean personal records is no longer optional.
- A reported sum is not your profit—reported figures are proceeds and transactions, while acquisition costs are known only to your documentation. Without your own records, you negotiate against a figure you cannot counter. A portfolio tracker with tax reporting solves this.
Separating Proven Facts from Unverified Claims
Several narratives circulate; distinguishing them is crucial for your judgment.
- Proven: The notification to affected customers with the list of data fields (Revolut sent it; BleepingComputer reproduced it verbatim). Public surfacing of ID documents and verification selfies (confirmed by an affected customer to Cointelegraph).
- Claimed: The extortion threat of daily publication (from a Telegram post by alleged perpetrators). Revolut does not confirm it; a company under extortion rarely does. Always attribute the claim to its source.
- Disputed: An older summer episode where a database allegedly holding tens of millions of Revolut records was offered on dark web forums. Revolut denied authenticity, attributing it to compiled material from other sources. Keep this separate from the current incident; conflating them inflates the number of affected customers without evidence.
Practical takeaway: Expect highly convincing phishing. Knowing your name, date of birth, IBAN, and recent transactions allows attackers to craft sophisticated lures. The only reliable test is the channel, not the content. A genuine bank never asks via email or phone to move funds to a “security account,” enter a recovery phrase, or install remote access software. At the slightest doubt, use the app you installed yourself.
Self-Custody as a Consequence: Shortening the Data Trail
This case exposes a property of custodial arrangements invisible in daily use: holding crypto with a provider leaves a complete identity file alongside your balance. That file is the breach’s actual subject. A hardware wallet doesn’t eliminate all risks but shortens the trail at a decisive point: your balance no longer sits with a third party, so that party’s failure or breach no longer separates you from your coins.
Stay honest about trade-offs. The purchase itself generates data, as the Trezor breach showed; avoid shipping to your home address if possible, and buy only from the manufacturer or authorized resellers. The transfer from an exchange to your wallet is visible on-chain and linkable to your account statements. Responsibility for the recovery phrase then rests entirely with you. Self-custody shifts risk; it does not abolish it.
For funds remaining on a platform, selection hinges on supervision and custody practices. Ask about segregated custody, the custodian’s identity, and the license under which they operate.
Revolut Data Breach: Key Takeaways
- Establish exposure in writing. Send the Article 15 GDPR access request today and record the date. Without that list, you’ll later argue over assumptions. Simultaneously, check which trading venues hold your ID copy and close unused accounts; our regulated crypto exchange overview highlights what matters for those you keep.
- Separate identity and holdings. Use fresh receiving addresses, avoid merging old and new holdings in single transactions, and move long-term holdings into your own custody. Our hardware wallet comparison details devices and their weaknesses.
- Order your records before the first DAC8 report. Complete acquisition data is your only counter-argument against reported sums from the 2026 reporting period onward. A tax and portfolio tracker automates the collection.
As of September 14, 2026. This article is not investment advice. Prices and fee structures change; verify terms with the provider before purchasing.