Revolut just confirmed that someone walked away with the passports, home addresses, and full Bitcoin transaction histories of an unknown number of its customers. They didn’t need to hack anything to get it. They just asked, using an email address that belonged to a real government agency.
The fintech, which serves more than 80 million customers worldwide, disclosed the incident this week after a third party impersonated a government body to request customer files. Revolut handed them over. The story lands at an awkward moment: on-chain crime trackers have spent 2026 documenting a sharp rise in violent, physical crimes against crypto holders, and this is close to a textbook version of the data trail those attacks are built on.
What Revolut Actually Confirmed
According to TechCrunch’s reporting, which reviewed the notification Revolut sent to affected customers, the exposed data included birth dates, postal and email addresses, phone numbers, copies of passports and driver’s licenses, verification selfies, account statements, IBANs, and complete transaction histories, specifically including Bitcoin activity.

A Revolut spokesperson told TechCrunch the company “recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” The email reportedly passed Revolut’s own authentication checks because it genuinely originated from within that agency’s mail infrastructure, not a lookalike domain.
Revolut says the number of affected customers is “limited,” that it has blocked the address, notified the agency, law enforcement, and regulators, and that customer funds and systems were never at risk. The company has not said which government agency was impersonated, how many customers were affected, or which countries they’re in.
Why This Specifically Threatens Bitcoin Holders
A breach of postal addresses alone is bad. A breach that also links a named, addressed individual to their exact Bitcoin holdings and wallet history is a different category of risk, because it turns a database leak into a target list for people who show up at your door rather than your inbox.
That distinction is exactly what on-chain crime researchers have been warning about all year. Physical coercion attacks on crypto holders (home invasions, kidnappings, and armed robbery aimed at forcing a wallet transfer, often called “wrench attacks” after the webcomic that named the tactic) have been rising sharply through 2026, and every version of that crime starts with the same input: knowing who holds crypto and where to find them.
The Numbers Behind the Warning
Blockchain security firm CertiK’s own Intel3D research team tracked 52 verified wrench attacks worldwide in the first half of 2026, up 33.3% from the same period in 2025. Recorded financial exposure across those incidents (ransom demands, forced transfers, frozen and recovered funds combined) reached approximately $124.1 million, an 11.8-fold jump from H1 2025’s $10.5 million.

CertiK’s data also shows a tactical shift: home invasions specifically jumped from a single recorded case in H1 2025 to 20 in H1 2026, now the single largest attack category. Europe accounted for 39 of the 52 global incidents, with France alone responsible for 33, roughly two-thirds of the entire worldwide total.
Family Members Are Now Targets Too
Blockchain analytics firm Chainalysis has separately documented a related shift in tactics: attackers increasingly go after a holder’s relatives rather than the holder directly, using them as leverage to force a transfer. According to Chainalysis’s own H1 2026 wrench-attack research, incidents targeting family members or close acquaintances made up roughly 25-30% of cases globally by early 2026, up from near zero in 2021.

That France-specific number is worth flagging because it’s easy to see it repeated online as if it were the global rate, when Chainalysis’s own data draws a clear line between the two: globally it’s 25-30%, and it only crosses 40% inside France specifically, where a 2026 tax-authority data breach and a separate breach at a crypto tax-reporting firm reportedly supplied attackers with ready-made target lists.
None of this means a Revolut account or a Bitcoin ETF share is inherently more or less dangerous than self-custody. Each just shifts where the risk sits rather than removing it. What this week’s breach actually demonstrates is narrower and harder to argue with: the data trail connecting a real name to a real amount of Bitcoin is now valuable enough, and leaks it enough, to be showing up as raw material in violent crime statistics, not just theoretical privacy concerns.












