The person trying to steal your Bitcoin may know your home address before they ever ask about your wallet.
They may know your full name, your phone number, the bank you use, and the date of a transaction you barely remember. They may have a copy of the passport you uploaded years ago because opening an account required it.
Meanwhile, your hardware wallet can be working perfectly.
Your recovery phrase can remain offline. Your private keys can remain secret. The protections you spent years learning can still be doing exactly what they were designed to do.
That is what makes the latest Revolut incident so uncomfortable. It exposes a security problem that survives even when the cryptography holds.
You can take your Bitcoin off an exchange without taking your identity out of its records.
Forget interest rate cuts. The real war brewing behind the scenes will split the world, destroy money as we know it, and redefine wealth. Welcome to the decade of fractures.
On September 12, 2026, Revolut confirmed that fraudulent requests sent through a legitimate government agency email domain had led it to disclose sensitive customer information to an unauthorized third party. The company said its systems and customer funds were unaffected.
That reassurance matters. It also leaves a question hanging over everyone whose information was disclosed: what can someone do with the data now?
According to the Financial Times, Revolut contacted approximately 680 customers following its initial investigation. That is a reported figure, rather than proof that every affected person held Bitcoin or that every record contained the same information.
Customer notifications described information that could include identity documents, addresses, verification images, account statements, IBANs, withdrawal records, and transaction histories, including Bitcoin activity. The categories potentially exposed went well beyond the details someone might find on a public social profile.
A passport connects the account to a person. A home address locates that person. Financial records add context about their money. Where a record identifies an on-chain withdrawal, it may also provide a starting point for investigating activity on Bitcoin’s public ledger.
None of those things is a private key. Together, they can still be valuable to someone trying to get your money.
The Financial Times subsequently reported that people claiming responsibility said they had used access involving Italy’s certified-email system, PEC, to impersonate law enforcement and obtain information over a period of months. They said wealthy cryptocurrency holders were of particular interest.
Those are attributed claims, and they should not be inflated into a proven compromise of Italy’s entire PEC infrastructure.
The essential problem is already serious enough.
A trusted communication channel helped an unauthorized request look legitimate.
Think about where the security boundary failed. A financial company holds sensitive records. It has processes for responding to requests from authorities. An attacker presents a request that appears to arrive through an official channel, and the company releases information.
The data leaves through a process built to handle legitimate disclosures.
This route predates the Revolut incident. In November 2024, the FBI warned that criminals were using compromised government email accounts to submit fraudulent emergency data requests to companies. Its advisory described the exposure of personal information and urged more careful validation of suspicious requests. That history makes this week’s news a fresh example of an established threat.
There is an obvious lesson for institutions:Authenticating an email’s technical origin does not settle whether the person sending it has authority to obtain the requested information.
There is a closely related lesson for customers.
Knowing accurate details about your account does not prove that someone contacting you works for your bank.
The same confusion can appear at both ends of the attack.
First, an institution trusts the apparent authority behind a request. Later, a customer may trust someone who possesses information that seems too private for a stranger to know.
That second step is where a data leak can become a Bitcoin theft.
Imagine receiving a call after learning that your details were exposed. The caller knows your name, your account information, and the date of an actual Bitcoin withdrawal. They refer to the real incident and say they are helping affected customers.
The facts sound right. The timing sounds right. Their explanation seems to fit the problem you already know exists.
Then comes the request: move your Bitcoin to a wallet they describe as secure.
This is an illustrative scenario, not a claim that it happened to the Revolut customers in this incident. But the underlying sequence is documented elsewhere.
In May 2025, Coinbase disclosed that criminals had bribed overseas support personnel to obtain customer information for social engineering. The company explained that the attackers wanted to impersonate Coinbase and persuade customers to send them cryptocurrency. Its announcement distinguished the absence of exposed private keys from the losses suffered by customers deceived into transferring funds.
That distinction should change how we read the sentence “funds are safe.”
It can describe an important fact about the immediate incident. It cannot guarantee the future safety of every person whose information has escaped.
A hardware wallet protects signing keys. It cannot determine whether the convincing person on the phone deserves your trust. If you authorize a transfer to an attacker’s address, the transaction can satisfy Bitcoin’s rules even though the story that persuaded you to make it was a lie.
The attacker can leave your private keys secret and still persuade you to use them against yourself.
This is why treating every data incident as harmless until coins move sets the threshold too late.
By the time a fraudulent transaction appears on-chain, the useful intervention may already have been missed: recognizing the impersonation, questioning the request, or refusing to make a financial decision under pressure.
The value of the stolen information lies partly in its ability to make those interventions less likely.
A generic scam asks for trust. A targeted scam can arrive carrying evidence.
The same separation between money and information appeared in another disclosure this week.
On September 14, Swiss Bitcoin Pay said it had temporarily shut down its servers after suspected unauthorized access to internal systems. The company said customer email addresses, Bitcoin addresses, IBANs, transaction histories, and hashed passwords might have been accessed. It also said user funds were safe and amounts owed would be returned. The scope remained under investigation.
These are separate incidents. There is no basis here to claim a shared attacker or a common technical cause.
They do, however, raise the same question:How much sensitive information can a service expose even when the incident does not directly give an attacker control of customer funds?