A spoofed government email got Revolut to release KYC files and full Bitcoin transaction histories. No server was breached. The lesson is about who holds the file, not about Revolut.

On 12 September 2026, Revolut confirmed it had disclosed a set of customer records to someone who asked nicely from the right email address.
The request arrived from a mailbox operating inside a real government agency's domain, carrying valid domain authentication. It passed every automated check an email is supposed to pass, because on paper it was legitimate mail from a legitimate domain. Staff treated it as the law-enforcement order it appeared to be and released what was asked for.
What went out: passport copies, verification selfies, full names, dates of birth, contact details, IBANs, withdrawal histories — and full Bitcoin transaction histories. Reporting indicates the request was aimed at high-net-worth users rather than scraped at random. Revolut says account passcodes and login credentials were not included, blocked the sender once the request was identified as fraudulent, and notified the agency, the police, financial regulators and data protection authorities.
No server was breached. No password was cracked. No malware was involved. The data left through the front door because there was a front door, and behind it sat a file with everything in one place.
It is tempting to read this as a story about Revolut's controls, and there is a version of that story worth telling. But the more useful question is the one that applies to every custodial account you hold:
What could this company be tricked into handing over about me?
For a custodial crypto account the answer is fixed, and it is known in advance. To operate legally, the provider must collect and retain a government ID, a biometric selfie, your address, and a complete record of your transactions. That bundle is a regulatory requirement. It is not optional, and it does not expire when you stop using the account.
Which means the bundle exists whether or not anyone ever attacks it. Social engineering, an insider, a misconfigured database, a subpoena real or forged — these are different routes to the same file. Reduce the odds on one and the others remain.
A non-custodial position has no such file.
There is no operator holding your passport, because no operator was required to see it. There is no support desk that can be persuaded to release your account history, because there is no account in the sense that a bank means it — only a keypair you control and a contract that does not know who you are. A spoofed subpoena addressed to a smart contract accomplishes nothing, because there is nobody there to read it and nothing on file to hand over.
That is the narrow, specific claim, and it is worth being precise about it:
self-custody removes the central file, not your exposure.
Here is what it does not do:
Anyone who tells you self-custody makes you invisible is selling something. The honest version is smaller and still valuable: there is no single document set, sitting in one company's systems, that can be released in one mistake.
Revolut is not an outlier here, and picking on any one company misses the pattern. Once identity documents are collected, they accumulate somewhere and they persist — usually with a third-party verification vendor rather than the brand you actually signed up with.
That secondary layer has its own track record. In November 2025 researchers found an identity-verification provider's database sitting on the open internet with no password, holding names, addresses, dates of birth and national ID numbers at a scale measured in hundreds of millions of records. In July 2024 a verification vendor serving crypto projects lost the passports, driving licences and facial images of tens of thousands of users to a compromised operator account, in an incident that lasted about two hours.
Neither of those companies is one most affected users had heard of. That is the point: you cannot audit a vendor you were never told about, and you did not choose it.
We have written separately about what happens to your ID after you upload it, including which incidents are documented and which are widely misreported.
Nothing here argues for abandoning regulated services. Fiat has to enter somewhere, and a licensed provider with real controls is the correct place for that to happen.
What it argues for is being deliberate about the split:
At JewelSwap, positions are non-custodial by construction. We do not hold your assets, we do not collect your identity documents, and we could not release either if someone asked us convincingly, because neither exists on our side. That is a design property rather than a promise about our staff — which is rather the point of this article.
Sources: The Block, CryptoBriefing, The Crypto Times, Cybernews, The Block on Fractal ID. Nothing in this article is financial advice.