Community Trust ScoreVerified
A hacker tricked Revolut into handing over passport copies and sensitive data belonging to 680 customers — then demanded 10,000 Bitcoin as ransom. The method was brazen: the attacker posed as a legitimate Italian law enforcement official, exploiting EU regulations that require companies to comply with certain data requests. Revolut, apparently convinced the request was real, handed the data over.
Lyudmyla Kozlovska of Open Dialogue flagged the mechanics of the attack. The hacker didn’t break through a firewall or brute-force a database. They just asked, wearing the right costume. And the system complied.
KYC’s Structural Problem
That’s kind of the whole issue with traditional Know Your Customer processes. They work by collecting massive amounts of personal data — passports, selfies, proof of address — and then storing it indefinitely. Every institution that runs KYC basically builds a treasure chest: full of real names, real faces, real document numbers. Hackers know this. That’s why financial firms are such attractive targets.
The Revolut breach didn’t happen in isolation. In 2026 alone, 343 million people in the United States were affected by data breaches. That’s not a rounding error. It’s a structural failure at scale, and it’s probably going to get worse before anyone fixes it.
The problem isn’t that Revolut did something uniquely reckless. It’s that the whole industry runs on a model that creates these vulnerabilities by design. Compliance teams collect more data than they need, store it longer than necessary, and then cross their fingers that their security holds. Often it doesn’t.
And the EU’s regulatory framework, meant to protect citizens, got weaponized here. The attacker knew that a company facing a formal-looking law enforcement request from within the EU has strong incentives to comply fast. Refusing risks regulatory blowback. So the hacker exploited that pressure. Smart, in a deeply cynical way.
Zero-Knowledge Proofs: Better in Theory
There’s a better approach sitting on the shelf, mostly unused. Zero-knowledge proofs — a cryptographic method that lets you verify something is true without actually revealing the underlying data — could change how identity verification works. Instead of handing over a passport scan, a user could prove they’re over 18, or that they’re a verified EU citizen, without the institution ever seeing the raw document.
The EU is already moving in this direction. Its digital identity frameworks are being built to support selective disclosure — the idea that you share only what’s needed for a specific transaction, nothing more. Digital Identity Wallets, still rolling out, are designed with this logic in mind. You prove your age to buy something age-restricted. You don’t hand over your full passport details for a transaction that doesn’t need them.
It’s a cleaner model. Less data stored means less data to steal.
But it’s not widely deployed in financial KYC yet. Not even close.
Why Adoption Is Stuck
The Financial Action Task Force — FATF — actually offers guidance that allows digital ID systems for customer verification without requiring physical document storage. So the regulatory ceiling isn’t as low as most institutions act like it is. But the guidance is ambiguous enough that compliance teams default to what they know: collect the document, store the image, move on.
That ambiguity is doing real damage. Institutions aren’t storing all this data because they want to. They’re storing it because no one has told them clearly that they don’t have to. And when regulators are vague, lawyers and compliance officers get conservative. Conservative means more data, longer retention, bigger targets.
Zero-knowledge proofs also face a practical wall: interoperability. For cryptographic identity verification to work across a financial system, every institution involved needs to accept and validate the same proofs. That requires shared standards. Right now, those standards aren’t widely established. A bank in Germany and a crypto exchange in Singapore aren’t working from the same playbook.
So the tech exists. The regulatory permission probably exists, at least partially. But the infrastructure to make it all work together — that’s still missing.
Meanwhile, compliance teams keep doing what compliance teams do. They collect passports. They store selfies. They build treasure chests.
And hackers, apparently, keep finding new ways to ask nicely for the keys.
The 10,000 Bitcoin ransom demand attached to the Revolut breach is still unresolved — no details on whether it was paid or refused.
Hub: Bitcoin price, news, and analysis
Frequently Asked Questions
What exactly happened in the Revolut data breach?
A hacker impersonated an Italian law enforcement official and used EU regulatory compliance obligations to trick Revolut into releasing sensitive customer data, including passport copies, affecting 680 customers. The attacker then demanded a 10,000 Bitcoin ransom.
What are zero-knowledge proofs and how do they relate to KYC?
Zero-knowledge proofs are cryptographic methods that let a party verify identity attributes — like age or citizenship — without the verifying institution ever seeing the raw personal data, which means less sensitive information gets stored and potentially stolen.
Why It Matters
This incident highlights significant vulnerabilities in the Know Your Customer (KYC) processes employed by financial institutions, particularly in the cryptocurrency sector, where regulatory compliance is critical. The breach not only raises concerns about the security of personal data in digital finance but also emphasizes the potential for high ransom demands in crypto, which can impact market confidence and the perceived safety of using digital assets. As ransomware attacks become more sophisticated, this case may prompt a reevaluation of data protection strategies within the industry.





