Revolut Data Breach: Your Files Are Public, and Here Is What You Can Do
Since September 14, the ID copies, KYC selfies and account statements stolen from Revolut have been published. What a password change no longer achieves, which rights the GDPR gives you, and why your Bitcoin history is the most sensitive part of the package.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
When a copy of your ID document, your verification selfie and your complete Bitcoin transaction history all sit in one package in the hands of strangers, a new password achieves almost nothing. That has been the position of the Revolut customers who received a breach notification since September 14, 2026: the stolen documents have been published since the early hours of that day. Four things matter now. Establish in writing how far your own exposure goes. Close the routes through which a copy of an ID document turns into money. Take the link between your home address and your crypto holdings seriously. And enforce your rights against the bank while the deadlines are still running.
This piece builds on our first assessment. Whether you are among the affected customers at all, and what role your Bitcoin history plays in the incident, is covered in Revolut data breach: am I affected, and what about my Bitcoin history? from September 12. This article deals with the stage after that: the details are out, and that changes the question of what to do.
Revolut data breach: what to do now that the files are being published
Until the weekend, the security incident was an outflow of customer data. Since the night of September 14, Cointelegraph has reported that copies of identity documents and verification selfies belonging to Revolut customers have surfaced online. According to the outlet, the attackers are announcing on Telegram that they will release further data sets every day until Revolut pays. One affected customer confirmed to Cointelegraph that the published details match the documents held on file at Revolut, and that the neobank wrote to him on Friday.
One point matters for the assessment: the existence of a ransom demand is the attackers' own account, relayed by a trade publication citing a Telegram post. Revolut itself does not confirm any such demand. A specific Bitcoin sum is also circulating on aggregator sites as the alleged ransom. There is no solid evidence for that figure, which is why it does not appear as fact in this article.
The practical difference from last week is considerable nonetheless. As long as a data set sits only with one criminal group, it needs a buyer before it can be used against you. Once it is publicly retrievable, that intermediate step falls away, and the number of possible fraudsters grows from one group to anyone who finds the file.
Which data fields Revolut lists in its customer email
The trade publication BleepingComputer quotes the notification Revolut sent to affected customers verbatim. According to that text, the incident covers the full name, date of birth, occupation, postal address, email address and telephone number. On top of that come copies of an identity card or driving licence, the selfies from the identity check, account statements including the IBAN, withdrawal records and the complete transaction history including Bitcoin transactions.
Revolut speaks of a limited number of affected users but gives no figure. According to the company, neither its own systems were compromised nor were customer funds touched. Both statements are plausible and both change little about your position. The damage from this incident does not hit your balance. It sits in the paperwork.
The outflow was triggered, on the company's account, by a forged request that looked like an information request from a government authority. Such emergency data requests are an established procedure: where there is imminent danger, authorities demand subscriber data without waiting for the regular judicial route. The forged request came from a genuine government domain and passed the technical sender authentication checks. That is exactly where the weak point sat. A technically correct signed email proves that the domain is genuine. It proves nothing about whether the request behind it is lawful.
Why a leaked ID scan is not a case for Germany's 116 116 blocking hotline
Many affected people reach first for the same reflex: have the ID card blocked. In Germany that runs through the free blocking hotline 116 116, and in this case it is the wrong step. What gets blocked there is the online ID function, the eID on the chip of your identity card. That function requires the physical card plus the six-digit PIN. A scanned copy cannot trigger it.
Your ID card is still in your drawer, and the eID is not the way in. The risk sits with every provider that accepts an image file of an ID document as proof: credit brokers, mobile operators, mail-order retailers offering purchase on account, and some trading platforms with weak checks. Blocking the eID would have no effect there and would only cost you the use of digital government services.
A different set of measures does work. File a criminal complaint with the police, online through the digital police station of your federal state; the case number is later your evidence towards any creditor chasing a claim taken out in your name. Request a free copy of your data from the major credit reference agencies and check whether contracts appear there that you never signed. And set yourself a reminder, because identity abuse using copies of ID documents often only shows up months later. The German Federal Office for Information Security sets out the individual steps for victims of data breaches and doxing in detail.

ID scan and KYC selfie together: the problem with the liveness check
An ID scan on its own is a known risk. The combination of an ID copy and the selfie from the same identity check is a different order of magnitude, because that pair is the standard proof used to open an account. Many providers require a photo of the document and an image of the face, and some match the two automatically.
The safeguard against this is called a liveness check, and it is meant to establish whether a living person is sitting in front of the camera or a photographed image. Good procedures demand head movements, changing light patterns or depth capture; weak ones make do with an uploaded still image. Wherever only a still image is required, a leaked verification selfie is immediately usable.
That produces a concrete task for crypto users: look up which trading venues hold your ID document, and close the accounts you no longer use. Every dormant registration is one copy of your paperwork less in circulation. Where you stay active, switch on two-factor authentication through an authenticator app or a security key rather than by SMS, because the phone number is part of this breach. Which platforms in Germany operate under supervision at all, and how to check that, is covered in our overview of regulated crypto exchanges.
Bitcoin transaction history in someone else's hands: what address clustering makes possible
The part of the package that separates this incident from an ordinary bank data breach is the transaction history. Bitcoin is a public database: every transfer sits in the chain for anyone to inspect. What the chain lacks is the link between an address and a person. An account statement with withdrawal records delivers exactly that link, free of charge.
Address clustering is the name of the technique that derives a whole bundle of addresses from a single known one: when several addresses appear together as the inputs of a transaction, they very probably belong to the same wallet. Anyone who knows one of your withdrawal addresses can work outwards from there and often arrives at an estimate of your total holdings. The technique is neither new nor illegal; analytics firms and investigators have worked with it for years. What is new is that the starting point for it is now lying around in public.
The obvious question is whether you should change your addresses. For future payments yes; for the past it cannot be done. A transaction once written into the chain cannot be retrieved. In practice that means: use fresh addresses for new incoming payments, avoid merging old and new holdings in a single transaction, and for larger amounts do not pay in and withdraw through the same platform.
Home address plus crypto holdings: putting the physical risk in perspective
The on-chain investigator ZachXBT reads the incident as one where the breach looks small but appears deliberately aimed at wealthy users. That is his assessment and not an established fact, but it deserves attention because it fits the structure of the data: postal address, date of birth and occupation together with a traceable Bitcoin history produce a profile that goes beyond the usual phishing purpose.
We have described this pattern twice already in our coverage, most recently in the Trezor data breach in September, in which names, phone numbers and home addresses of hardware wallet buyers were exposed. The lesson from it applies here just the same. Do not talk about amounts in the neighbourhood or on the phone. Treat parcel notifications and supposed callbacks from the bank's service team with suspicion, even when your name, your date of birth and your most recent debit are quoted correctly. Those details are precisely what is in the package, and a caller who knows them has proved nothing by doing so.
In concrete terms that also means setting yourself a callback rule at your bank and at your trading venues. No process that begins on the phone is completed on the phone. Hang up and dial the number from the app or from your account statement. That single habit strips most of the value out of what a cybercriminal can do with your documents.
What to do if your Revolut account has been hacked
One important distinction first: no account was taken over in this incident. According to the company, documents were handed out; login credentials were not stolen. If your account really is being controlled by someone else, a different procedure applies, and it begins with blocking.
Block the card in the app and, if you no longer have access, through the bank's customer service. Report every unauthorised debit without delay; under payment services law you are as a rule reimbursed for an unauthorised payment as long as you have not acted with gross negligence, and the bank has to prove the authorisation. Then change the password of your email inbox, because it is the master key to every other login. Finally, check the connected devices and sessions in every account that uses the same email address, and throw out any session you do not recognise.
Record every one of these steps in writing, with date and time. Anyone who later claims damages or disputes a demand needs that record.

The coming weeks: a review plan with fixed dates
Identity abuse after a security breach rarely starts immediately. Weeks, sometimes months, pass between the outflow and the first attack made in your name, because the data sets first have to be sorted, merged and passed on. A review plan with fixed dates therefore works better than a single frantic afternoon.
This week: send off the Article 15 access request, file the criminal complaint, and switch two-factor authentication everywhere to an app or a security key. Note down as well which postal addresses and which phone number were held on file at the neobank. Anyone who later receives a message quoting exactly those details will recognise at once which source the sender is drawing on.
In four weeks: request a copy of your data from the credit reference agencies and check it for entries you do not recognise; every credit enquiry you never made is a warning sign. In the same pass, go through the login logs of your most important accounts and report every access from a region you were not in.
After three months and after six: the same again. As long as your passport is in circulation as an image file, it keeps its value for fraudsters until its expiry date.
One expectation is worth dropping along the way. Checking services that promise to track down your data on the dark web are in reality searching a database of collections that are already known. Such systems give usable pointers about older incidents and still offer you no all-clear about a fresh one, because all they can show is what has already been traded in public. Rely on the information from your own Article 15 response rather than on a green light.
Your rights under the GDPR: access under Article 15, complaint under Article 77
The notification Revolut sent out is an obligation under Article 34 of the General Data Protection Regulation: where a breach is likely to result in a high risk to those affected, the company has to inform them without delay. That email, however, only tells you that you are affected, not to what extent.
You obtain the extent through Article 15 GDPR, the right of access. Ask in writing for a copy of the data processed about you and, expressly, for a statement of which categories were disclosed to which recipients. The deadline is one month and can be extended by two months if the company gives reasons. That response is the only solid evidence of what was actually handed out in your case, and it is free.
If no answer arrives, or an unusable one, Article 77 GDPR applies: a complaint to a supervisory authority, expressly including the authority where you habitually reside. For German customers that is the data protection authority of your federal state. The fact that Revolut Bank UAB is based in Lithuania and that the authority there is competent under the lead supervisory authority procedure changes nothing; your state authority accepts the complaint and passes it on. The German branch in Berlin is additionally supervised by BaFin, which is not, however, responsible for data protection.
On damages under Article 82 GDPR, the position in Germany has been clearer since the Federal Court of Justice ruling of November 18, 2024 (case reference VI ZR 10/24): the mere loss of control over your own data can amount to compensable non-material damage, without any abuse having to be proven. You do have to set out that loss of control yourself. The amount depends on the individual case, and the sums awarded so far sit in the low hundreds.
Is Revolut monitored by the tax office? What applies under DAC8 since 2026
This question comes up after every incident of this kind, and the answer has nothing to do with the breach. Nobody is being monitored. What has been reported automatically since January 1, 2026 is something else: Germany's crypto asset tax transparency act transposes the European DAC8 directive into national law and obliges crypto asset service providers to record and transmit tax-relevant customer and transaction data. The first reporting period is the 2026 calendar year, and the data goes to the Federal Central Tax Office by July 31, 2027.
For you that has two consequences. The details crypto providers hold about you will grow rather than shrink, and keeping clean records of your own is no longer optional. A reported sum is also not your profit: what gets reported are proceeds and transactions, while the acquisition costs are known only to your own documentation. Anyone who does not keep it is later negotiating against a figure they have nothing to set against it. A portfolio tracker with tax reporting solves exactly that problem.
Extortion, ransom, millions of records: what is proven and what is not
Several narratives are running alongside each other around this security incident, and the differences matter for your own judgement.
Proven is the notification to those affected together with the list of data fields, because Revolut sent it out itself and a trade publication reproduces it verbatim. It is also proven that copies of identity documents and verification selfies have surfaced publicly; one affected customer confirmed the match to Cointelegraph.
Claimed is the extortion. The threat of daily publication comes from a Telegram post by the alleged perpetrators. A company being extorted rarely confirms it, and Revolut does not do so here. Anyone mentioning the demand should say who is making it.
Disputed is an older matter that is resurfacing: over the summer, a database allegedly holding tens of millions of Revolut records was offered on the dark web in the relevant forums. German media reported on it, Revolut denied its authenticity and pointed to material compiled from other sources. That episode has to be kept separate from the current one. Anyone who throws the two together arrives at a number of affected customers that nobody has evidenced.
For handling the days ahead, that means: expect phishing that looks very convincing. Whoever knows your name, date of birth, IBAN and most recent transactions no longer writes a clumsy spam email. The only reliable test remains the channel, not the content. A genuine bank never asks you by email or telephone to move funds to a security account, to enter a recovery phrase or to install remote access software. At the slightest doubt, go through the app you installed yourself.
Self-custody as a consequence: when a hardware wallet shortens the data trail
This case exposes a property of custody arrangements that stays invisible in everyday use: anyone holding crypto assets with a provider leaves behind a complete identity file there alongside the balance. That file is the actual subject of the incident. A hardware wallet does not change all of it, but it does shorten the trail at one decisive point: the balance no longer sits with a third party afterwards, and that third party's failure or data breach no longer separates you from your coins.
It is worth staying honest all the same. The purchase itself generates data again, as the Trezor breach mentioned above shows; so never order to an address that is also where you live, if you can avoid it, and buy only from the manufacturer or authorised resellers. The transfer from an exchange to your own wallet is also visible in the chain and can be linked to your account statements. And responsibility for the recovery phrase then lies entirely with you. Self-custody is a shift of risk, not its abolition.
For whatever is meant to stay on a platform, selection comes down to supervision and custody practice. Ask about segregated custody, about who the custodian is, and about the licence under which that custodian operates.
Revolut data breach: what to take away
- Establish your exposure in writing. Request the Article 15 GDPR access response today and note the date you sent it. Without that list you will later be arguing over assumptions. In parallel, check which trading venues hold a copy of your ID document and close the accounts you do not use; our overview of regulated crypto exchanges shows what matters with the ones you keep.
- Separate identity and holdings. Use fresh receiving addresses, do not merge old and new holdings in a single transaction, and move the part you hold long term into your own custody. Our comparison of hardware wallets names the devices along with their weaknesses.
- Get your records in order before the first DAC8 report goes out. Complete acquisition data is your only counter-argument against a reported sum from the 2026 reporting period onwards. A tax and portfolio tracker takes over the collecting.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Revolut Data Breach: Am I Affected, and What About My Bitcoin History?
- Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
- Bitcoin From a Foreign Exchange to Austria: Which Tax Data You Need
- Man Who Bought 2 Pizzas for 10,000 BTC Does It Again
- How to Buy Bitcoin with No KYC in 2026: 3 Ways to Do It
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 11, 2026 10:18 AM

Bitcoin Tax Audit: What Proof Austria Requires
Which bitcoin records can the Austrian tax office examine? Purchase dates, wallet transfers, acquisition costs and sale proceeds are what count.
August 22, 2019 9:55 AM

Here’s why you should skip Facebook’s Crypto: Instagram Data Breach
It’s practically similar to stating the sky is blue yet we have another Facebook Data Leak close by influencing a huge number of clients. This time around, it includes the contact data of in excess of 49 million Instagram Accounts […]
September 17, 2026 7:12 PM

Gifting Bitcoin to Children: Allowance, Holding Period and the Tax Office Report
Transferring Bitcoin to your child hands over your holding period and your entry price along with the coins. This guide sets out what really applies in Germany on the allowance, the reporting deadline, representation and custody.
February 3, 2026 4:30 AM

5 Things to Do During a Crypto Market Crash
Navigate crypto market crashes with confidence. Learn essential strategies to protect your investments and capitalize on potential opportunities.
February 24, 2019 1:31 PM

MEW Launches KYC-less Crypto-to-Fiat Platform
Cryptocurrency wallet MyEtherWallet (MEW) in association with crypto investment company Bity has launched a platform to convert cryptocurrency to fiat without Know Your Customer (KYC) specifications. MEW declared the news in a blog post issued on Feb. 20. According to […]
May 15, 2026 9:47 AM

Top 10 Altcoins to Buy in May 2026 as Bitcoin Recovers
Here are the top 10 altcoins to buy in May 2026 as Bitcoin rebounds near $80K and market momentum shifts.
June 24, 2024 8:16 PM
Bitcoin News Today: Bitcoin CRASH OVER or MORE Down To Go?
Bitcoin Price Crash below 60k, and the crypto market follows. Why this decline and how low can it go?
December 5, 2024 11:00 PM

BGB Price Prediction: Bitget Token Price UP by more than 25%
Bitget is a top crypto exchange, with its native token BGB surging over 24% in the last 24 hours. Learn why Bitget stands out, what BGB offers, and how you can get started.
February 11, 2019 11:10 PM

Bitcoin Lightning Network Touches 6,000 Nodes
Bitcoin’s mainnet Lightning Network has touched a new milestone across the community as its speedy completion advances in the year 2019. According to a data monitoring website, the amount of active nodes at 6124, with 24,458 channels, and the Lightning […]
December 6, 2018 6:30 PM

The Cryptocurrency Timeline
A decade ago, Bitcoin’s secret founder Satoshi Nakamoto promulgated a paper called “Bitcoin: A Peer-to-Peer Electronic Cash System.” For those who haven’t been following crypto world closely, below is the timeline of the history of the crypto world so far. […]
August 16, 2026 9:11 PM

Swapping Bitcoin for Stablecoins: Does Austria Charge Tax?
Anyone swapping bitcoin for USDT or another stablecoin usually pays no tax in Austria yet. When the swap does become taxable after all.
August 21, 2026 1:33 PM

Bitcoin With No Cost Basis: How Austria Taxes the Sale
Bitcoin purchase price no longer provable? How Austria works out the capital gains tax, when a flat-rate cost basis applies and what investors can do.
August 20, 2026 4:12 AM

Wrapped Bitcoin in Austria: Is Converting BTC to WBTC Tax-Neutral?
Swapping BTC for Wrapped Bitcoin: when the move to WBTC can be tax-neutral in Austria, and which tax risks investors should know about. Acquisition costs carry over, but the classification of the token decides the outcome.
September 1, 2026 1:25 PM

Bitcoin Tax Report Wrong: What Austrian Investors Can Do
Errors in a Bitcoin tax report are not unusual. This is the data Austrian investors should check, and how a wrong capital gains tax deduction is put right.
August 28, 2026 10:15 AM

Selling Bitcoin Privately: What Tax Applies in Austria
Selling bitcoin directly to another person? In Austria, private sales can still trigger 27.5 percent tax on the realised gain.
March 27, 2025 5:00 AM

Bitcoin or Stablecoins: Which Is the Best to Hold in 2025?
GameStop adds Bitcoin to its treasury while Fidelity explores launching a new stablecoin. But what's in it for investors, and which is the best to hold in 2025?
November 11, 2024 7:25 PM

Bitcoin Price Prediction: BTC Price of $86,000 REACHED! What Next?
Bitcoin has shattered its previous record, skyrocketing past $86,000 and reigniting a buying frenzy among crypto investors.
April 5, 2025 3:03 PM

Cardano Price Prediction 2025: Will BTC Integration Push ADA Price to $3 or $5?
Cardano price predictions for 2025 are heating up, with analysts pointing to a possible breakout between $3 and $5. And with the recent announcement by Charles Hoskinson, what to expect for ADA price?
March 26, 2026 6:00 PM

Is Your Bitcoin Really Bitcoin? The Truth About Wrapped and Staked BTC
Wrapped and staked Bitcoin are growing fast in DeFi—but are they real BTC? Discover the risks, differences, and what investors must know.
August 5, 2024 10:58 AM

What Are The Reasons Driving The CRYPTO MARKET CRASH?
The recent crypto market crash, starting with the major fall of Bitcoin and followed by major Altcoins has been fueled by multiple factors...Here are the major ones...
August 25, 2026 10:13 AM

Gifting Bitcoin in Austria: When You Must Report the Gift
Austria levies no general gift tax on bitcoin. Above certain value thresholds, however, a notification to the tax office can be required.
January 29, 2025 8:00 AM

FOMC and Crypto: How Can the First FOMC Meeting Under Trump Affect the Crypto Market?
The first FOMC meeting under President Trump is set to take place tomorrow. Discover all possible scenarios and their impact on Bitcoin and the crypto market.
January 28, 2026 12:56 PM

Top 5 Altcoins to Buy in February 2026: Massive Discounts from ATH
With Bitcoin consolidating around 90K, discover the top 5 altcoins currently trading at a massive discount from their all-time highs for February 2026.
September 26, 2026 4:11 AM

Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
Three researchers published a draft for encrypted Bitcoin transfers without a soft fork on September 24, 2026. What Shielded Bitcoin hides, what stays public and which points you can check on your own wallet today.
March 25, 2025 3:00 AM

BREAKING NEWS: Visa and OpenAI to Partner for Stablecoin Payments
With the Fed pivoting, the SEC softening its stance, and Visa exploring crypto wallets with Sam Altman, could Bitcoin hit $250K?
More from CryptoTicker




