Revolut will cover the fees if customers hit by the data theft need new identity documents. Béatrice Cossa-Dumurgier, the bank’s head of Western Europe, said so on October 7, 2026 in an interview with the French broadcaster BFM TV; the news agency Reuters reported the pledge the same day. The breach affects 680 customer accounts. Cossa-Dumurgier gave no estimate of the total cost, and she did not say whether any customers have already replaced their papers.
Anyone who holds cryptocurrencies and is among those affected has a second problem that has nothing to do with the fee for an ID card. According to the reports, what left the bank were copies of identity documents, address data and account statements, which is precisely the data set needed to reconstruct an identity in front of a service provider. This article places the pledge in context, states the documented figures and shows which steps are open in Europe.
Revolut covers the ID document fees: where things stand as of October 7
The pledge is brief and comes without a procedure. According to Reuters, Cossa-Dumurgier said Revolut would take care of the associated costs should affected customers ever have to replace their identity documents. An application route, a deadline and an upper limit are not part of that statement. Anyone wanting to make use of it should approach the bank’s support team and have the case confirmed in writing, because a pledge in a television interview is not a published reimbursement policy.
In the same interview, the head of Western Europe drew two lines: the bank’s own systems had not been compromised, and Revolut would not pay a ransom. Public authorities are sometimes the weak link in the chain, she said, referring to the route by which the data left the bank. The pledge as the agency report words it contains no figure for how many of the 680 affected customers live in Germany.
What the cost cover does not include
The fee for a new document is the smallest item in this case. Replacing an ID card does not undo the fact that a date of birth, an address, an occupation and account movements now sit with third parties; none of those details changes with a new card chip. So anyone who only gets the fee reimbursed has settled the part of the damage that can be expressed in euros.
680 affected accounts and five months of access: the chronology of the data leak
The case is considerably older than the ransom demand. According to the analysis by SecurityWeek, the access spans a period of five months, 680 accounts are affected, and the demand amounted to around three million dollars. Of the 680 affected customers, 55 live in France according to the Reuters report; Revolut is said to have offered help to all 680.
The matter became public in September 2026, when the attacker group set a deadline and threatened to sell the data. We reported on that phase at the time, including the question of how those affected can place their own status: Revolut data breach: am I affected, and what about my Bitcoin history? The pledge on ID document costs is the bank’s first step that goes beyond information and actually costs money.
The figure of 680 is a floor, not a final count
SecurityWeek lists the 680 accounts as high-profile accounts. Whether the figure holds once the review is complete is open; with access running over five months, the count depends on which disclosures are retrospectively identified as unauthorised. A higher figure is therefore possible, but the sources reviewed offer no confirmation of one.
A hijacked government address as the way in: how the attackers reached the data
By its own account, Revolut handed customer data to an unauthorised party after information requests arrived from an email address carrying a public authority’s domain. According to the reports, the attackers controlled the email system of an Italian authority in order to do so. Technically, that describes no break-in to the banking systems. What was abused is a procedure that banks have to serve for law enforcement agencies every day.
Italy’s interior minister has criticised Revolut for it: the bank should have checked more carefully whether the request really came from the Italian government. That assessment is his, not ours; whether a breach of duty follows from it is for the supervisor and the courts to settle, not for an editorial team.
Why this route is so hard to defend against
An information request from a law enforcement agency comes from outside by definition, carries urgency, and must not be noticed by the customer. Those three properties are exactly what strips the bank of its usual counter-checks: asking the customer is ruled out, and the sender domain looks genuine for as long as the authority’s own mailbox sits under someone else’s control. A second channel for verification, such as a call back on an independently obtained official number, is the point at which this attack fails.
From passport to verification selfie: which data fields were taken
The reports describe a data set that reaches far beyond name and account number. It covers full names, dates of birth, occupations, addresses and contact details, along with passports and driving licences, account statements as well as facial verification images and transaction histories. Taken together, that is a complete identity file with a financial profile attached.

A card number can be blocked and replaced within days. A date of birth cannot, an address only by moving house, and a facial image not at all. That is where this incident genuinely differs from ordinary card fraud: the fields that leaked stay usable for years.
Why a KYC data set weighs more heavily than a card number
An account at a bank or a crypto exchange is opened by way of an identity check, and that same check serves many services as their emergency exit when somebody has lost access. The mechanism this creates explains the rest of this article, and it runs through three stages.
Credibility comes first. A caller who knows a date of birth, an address, an occupation and the most recent account movements does not sound like a fraudster but like the case officer he claims to be. The account statements supply the details that nobody outside the bank would otherwise hold.
Access follows. Wherever a service ties account recovery to a copy of an ID document and a selfie, both building blocks now sit with third parties. The transaction history additionally shows which accounts are worth the effort, because it reveals where money has flowed and on what scale.
What remains at the end is the risk away from the network. A documented home address next to a documented level of wealth is the precondition for the attack the industry describes as a wrench attack, meaning physical coercion instead of a technical detour. The attacker group claims it selected customers with larger crypto holdings via blockchain analysis; that selection is not documented, it comes from the perpetrators themselves, and it still explains why this data set is judged differently in the crypto scene than a trade in addresses.
6,000 Monero as ransom: the equivalent at today’s price
The group that gave itself the name “iamnotavillain” demanded 6,000 Monero according to reports in the Financial Times, and set a deadline of 24 hours. At the time of the demand, that corresponded to around three million dollars. Monero trades at $527.46 on October 10, 2026; calculated at that price, 6,000 XMR come to roughly $3.16 million. So the demand has risen slightly in dollar terms without the attackers changing anything.
The choice of currency is part of the threat. Monero obscures amounts and participants within the protocol itself, which is why the payment trail that makes an investigation possible with Bitcoin is missing. According to the Reuters report, Revolut has stated it will pay no ransom, while also saying it has had no direct contact with, and received no demand from, the group claiming responsibility for the incident. Both statements stand side by side, and the sources do not resolve the contradiction.
Data was stolen, not balances
According to the reports and to Revolut’s own account, no funds left the bank. The damage lies in the identity and account information, not in an emptied account. That distinction matters for placing the case: a financial loss can only arise later, in the place where the data carries a second attack.
46 euros for a German ID card: what the cost cover actually buys
Since February 7, 2026, a German ID card has cost 46 euros for applicants aged 24 and over, up from 37 euros; the Bundesrat approved the increase on January 30, 2026, and municipalities have published it since. For applicants under 24, whose card is valid for six years, 27.60 euros is due. A provisional ID card costs 10 euros, and direct delivery to the home address adds 15 euros.
The fee for a passport cannot be documented for 2026 from the sources reviewed, because the amounts given there still carry the old ID card price of 37 euros and therefore predate the increase. Anyone wanting to replace a passport should ask the responsible local registration office for the fee instead of relying on a figure from a guide. For reimbursement by Revolut, what counts in any case is the fee notice from the office, not an estimate.
Replacing the document solves only half the problem
A new ID card carries a new document number, and the old number loses its validity. That removes the part of the misuse which depends on a valid number, such as a new registration involving a document check. The facial image from the verification, by contrast, stays usable, and so does the address for as long as it is still correct.
Identity theft after a KYC leak: the attack routes in detail
Several attacks can be built from this data set, and they differ in what the perpetrators additionally need.
The call with insider knowledge
A caller poses as an employee of the bank, an exchange or a public authority and proves the role with details from the account statement. The aim is an authorisation, a code or a transfer to an allegedly secure account. No bank and no crypto exchange ever asks for a recovery code or the words of a wallet backup over the phone; that rule is the hard line at which such a call ends.
Recovering somebody else’s access
At many services, an ID image and a selfie are the proof that retrieves lost access. If both sit with third parties, the security of an account rests on the provider additionally requiring a factor that the data set does not contain, meaning a hardware key or an app on a specific device. Confirmation by SMS does not count, because a phone number can be ported to someone else’s device with a complete identity file in hand.
The route via the home address
An address next to a documented crypto holding shifts the risk from technology into the home. It helps to prepare by storing holdings so that a single handover does not cost everything, for instance by separating a small balance for everyday use from a larger one in self-custody.

GDPR compensation under Article 82: the legal framework for those affected in Germany
Article 82 of the General Data Protection Regulation gives every person a right to compensation for the material and the non-material damage suffered through processing that infringes the regulation. Article 34 obliges the controller to notify those affected of a data breach carrying a high risk, and Article 15 grants the right to information about which data is stored on a person and to whom it has been disclosed.
None of that establishes that an infringement occurred in the Revolut case. That assessment is for the competent supervisory authority and, in a dispute, the courts, and it hangs on whether the examination of the information request met the required standard. As an affected person, your rights under Article 15 are open to you regardless of that assessment, and a subject access request under Article 15 is the way to put your own exposure on the record rather than assume it.
Jurisdiction and supervision
Revolut runs its banking business in the EU on a Lithuanian banking licence and offers its services in other member states under the European passport. Affected customers can lodge a complaint with the data protection authority of their country of residence, in Germany therefore with the competent state authority; the authorities coordinate with one another during the procedure. Going through your own state authority is the shorter route, because it works in your own language and without a cross-border element.
Self-custody with a hardware wallet: how the attack surface shrinks
An account with a provider hangs on an identity check, and that very check is the weak point in this case. Self-custody inverts the relationship: there, possession of a device and knowledge of a backup decide access, and an ID image in someone else’s hands is no help with either. Which devices are candidates and how they differ is set out in our comparison of crypto hardware wallets.
The move has a flip side that fits this case. Anyone holding their own keys carries the risk of loss alone, and the backup words are then the only thing that counts. Those words belong neither in a photo nor in cloud storage, because a data set like the one that leaked here shows how far information travels once it exists in digital form.
What applies for tax when you move holdings
A transfer between your own wallets is not a disposal and triggers no tax in Germany. What matters is the documentation: the acquisition dates have to remain traceable, because the one-year holding period depends on them. Anyone moving holdings without records does not lose the period itself, but does lose the simple proof of it.
What has changed since the articles in September
In September, the question in the foreground was whether you are affected yourself and what a publicly released data set means. Two things have moved since then. First, as of October 7 there is a pledge from the bank that costs money and goes beyond advice. Second, SecurityWeek’s analysis documents the five-month period, which leaves the incident standing as longer-running access rather than a single mistaken disclosure.
Three points remain open that would be needed to close the case for German customers: how many of the 680 affected customers live in Germany, which route the reimbursement runs through, and whether the data was sold or published after the deadline expired. On none of these points do the sources reviewed supply an answer.
Our assessment: the cost cover is a signal, not compensation
In the editorial team’s view, the pledge is right and too small. The numbers make the case: 46 euros for an ID card stand against a data set that comprises a date of birth, an address, an occupation, account statements and a facial image, and of those fields, replacing the document renews exactly one, namely the document number. Five months of access and 680 accounts are also not an order of magnitude that can be settled through a fee refund.
Against that, on the account of every source reviewed, Revolut was the victim of an attack on somebody else’s government mailbox rather than of a break-in to its own systems. A bank that answers an information request from a law enforcement agency is discharging an obligation; the only question is how strictly it counter-checks while doing so. Whether the standard was sufficient here is for the supervisor to judge, and until then the pledge remains what it is: a first step that covers the fee and leaves the rest open. Crypto investments can lead to a total loss; this assessment judges the situation and recommends neither a purchase nor a sale.
Revolut data breach: ten years of validity, ten years of exposure
A German ID card is valid for ten years, six for applicants under 24. For that long, a leaked copy stays usable as proof if the document is not replaced. The next steps hang on that.
- Establish your exposure in writing and start the reimbursement. Request information under Article 15 GDPR from support, have the pledge on cost cover confirmed in writing in the same case, and keep the fee notice from the registration office. For the everyday balance on your phone, a look at the comparison of crypto software wallets is worth it alongside, because splitting holdings limits the damage of any single breach.
- Detach your logins from SMS codes. At every exchange and broker, switch the second factor to an app or a hardware key and review the recovery routes, because a phone number is attackable once someone holds a complete identity file. Which providers sit under European supervision and which safeguards they offer is shown by the overview of the best regulated crypto exchanges.
- Document the move into self-custody. Anyone withdrawing holdings from an exchange should record the date, the amount and the address so that the one-year period stays provable; a transfer between your own wallets remains tax-free. Tools for that are in the overview of crypto tax software and portfolio trackers.
(As of October 10, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)





Be the first to comment