A peculiar type of security breach has hit the neobank Revolut, highlighting the extreme vulnerability of compliance processes to social engineering cyberattacks. On September 11 and 12, the company responded to what appeared to be an official information request, believing it was collaborating with a government agency. In reality, an attacker had successfully infiltrated the messaging infrastructure of the state institution. The neobank's systems processed the message without any flags, as standard security controls such as SPF, DKIM, and DMARC confirmed the sender's technical authenticity. This incident comes as the institution, which recently secured a full banking license in France, eyes an IPO with a valuation estimated between $150 and $200 billion.
The scope of the stolen data is critical for the targeted users. The scam led to the exfiltration of complete identity files, including passport copies, facial verification photos, contact details, bank statements with IBANs, and, most notably, a comprehensive history of Bitcoin transactions. Based on observations by researcher ZachXBT and accounts from industry figures like Mark Karpelès and Marc Zeller, the attack primarily targeted wealthy clients. Although the firm claims to have blocked the compromised address and secured the funds, the simultaneous leak of personal identity records and digital asset history creates a lasting risk for the victims.
The joint disclosure of physical addresses and crypto-asset holdings poses immediate risks to personal safety. In France, violent extortion and kidnapping cases targeting digital currency holders have seen a sharp increase, reaching 77 documented cases since the start of 2026, compared to 45 for the entirety of 2025. This event echoes major past precedents in the sector, such as the 2020 Ledger hack or the 2025 internal leak at Coinbase, which resulted in total losses exceeding $400 million. In the current case, the definitive link between a real identity and a Bitcoin balance provides a particularly formidable targeting database for physical attacks.
The affair also reignites the debate regarding the efficiency and inherent risks of Know Your Customer (KYC) procedures, viewed by some in the ecosystem as vulnerable registries that put users in danger. While IT security audits cannot compensate for the lack of direct human verification when handling judicial requests, the incident demonstrates that the weak link remains the management of trust. While the firm has alerted financial regulators and the police, the affected French clients have the option to contact the CNIL directly to report this personal data breach under GDPR regulations.