Neobank Revolut finds itself at the center of a major security breach after unintentionally exposing sensitive personal information to malicious actors. By using a legitimate email domain belonging to a government agency, the attackers managed to bypass the fintech’s monitoring systems. While the company insists that its technical infrastructure was not directly hacked and that no funds were stolen, this sophisticated identity theft allowed for the fraudulent extraction of complete customer files.
The volume of compromised data is particularly concerning, going far beyond a simple leak of emails or login credentials. The exposed information includes passport scans, biometric verification selfies, IBANs, and full transaction histories, including those involving Bitcoin. This level of detail, which comprises the full file required for KYC (Know Your Customer) procedures, leaves victims extremely vulnerable, both in terms of their digital identity and physical security.
Analysis of the incident suggests that the attackers deliberately targeted high-net-worth profiles. This modus operandi reinforces fears regarding the rise of physical assaults targeting cryptocurrency holders, a trend seeing a sharp increase in France, with over 80 cases recorded since the beginning of 2026. The combination of residential addresses and precise digital asset histories provides criminal networks with actionable intelligence for targeted extortion or kidnapping, calling into question the effectiveness of current security protocols in the face of real-world risks.
This incident comes at a pivotal moment for Revolut, which is aiming for an IPO and continuing its global banking expansion. As the company prepares for its U.S. rollout, the data leak highlights a structural weakness linked to the massive centralization of sensitive information. Given the recurring nature of these breaches across various providers, the industry is now closely watching the emergence of alternative solutions such as Zero-Knowledge Proofs, which could eventually allow for customer identity verification without the need to store such critical documents on centralized servers.