October 8, 2026
Chargeback X ad
Revolut Risk

The Revolut Breach: One More Thought on Risk 

Sponsored Content

I am writing this in September, while everyone is still talking about the Revolut breach. By the time you read it, another scam, breach or AI tool may be dominating the conversation. So rather than write another postmortem, I want to use the case to think about something broader that has to do with risk.

The information reportedly disclosed did not just identify customers. It connected passports, addresses and bank details with Bitcoin transaction histories and wallet references. The Financial Times reported that about 680 customers were affected and that the people claiming responsibility said they had used blockchain analysis to identify customers with significant crypto holdings. Revolut has not confirmed that account.

Compliance data can become targeting data.

‘Money Out’ Always Worried Me More 

In my own compliance work, when crypto met traditional finance, the direction that worried me most was usually the off-ramp.

Someone arrives with crypto of uncertain provenance and wants to turn it into fiat. Where did the funds come from? Which wallets did they pass through? Are we looking at fraud proceeds, sanctions exposure, mixers or layering? Those are still real anti-money laundering questions, but Revolut made me think harder about the other direction.

When a regulated institution links a verified customer to on-chain activity, it creates a bridge between a real person and a pseudonymous public ledger. We need that bridge.

But once we build it, we have also created something valuable to somebody with different intentions. A wallet address on its own may tell you little about the person behind it. A home address tells you nothing about someone’s crypto holdings. A passport does not tell you how wealthy its holder is. Put them together, and the nature of the information changes.

That seems obvious once you say it out loud. I am just not sure I had previously treated it as a financial-crime risk in its own right. I do now.

The Risk Is in the Linkage

Privacy and intelligence practitioners have long dealt with versions of this as the aggregation problem or the “mosaic effect”: pieces of information that are limited alone become more sensitive when combined.

I don’t think I am inventing a new privacy concept. I do think AML and fraud teams need to take more ownership of it. I have started thinking about it as linkage risk.

Modern fintechs are good at creating these links. An institution may know who you are, where you live, which financial accounts you use, what assets you hold and which crypto activity or wallets belong to you.

It can become a detailed map of someone’s financial life across institutions. The risk is not necessarily any individual point on that map. It is the map itself. None of this makes me question know-your-customer controls. KYC helps us protect the financial system from the customer. It should also require us to protect the customer from what we now know about them.

Concentration Is a Risk

That is the version Revolut illustrates. One institution holds enough information to assemble the picture. If someone succeeds in getting that institution to disclose it, they do not need to piece the customer together themselves.

Crypto makes the potential consequences uncomfortable. Coinbase disclosed in 2025 that criminals had bribed overseas support staff to provide customer information, including identity and financial data, before attempting to extort the company. The rise in so-called wrench attacks — robberies, home invasions and kidnappings targeting crypto holders — is another reminder that identifying someone with substantial digital assets can create risks beyond phishing or account takeover.

I would treat records linking an identity to crypto activity as more sensitive than an ordinary KYC file, with a higher threshold for access, downloads and external disclosures.

Revolut also gives us one practical control lesson. The company said an “unauthorised third party utilised a legitimate government agency domain email” to make the requests. Requests from authorities for information this sensitive should be verified through a separately sourced contact. The domain can be genuine and the request can still be fraudulent.

Fragmentation Is Another Problem

The opposite problem is developing as crypto on-ramping becomes infrastructure.

More wallets, apps and fintechs now offer crypto purchases through networks of third-party providers. The company whose interface I am using may not be the company doing the KYC, moving the fiat or executing the crypto transaction.

The U.K. Financial Conduct Authority has described MLR-registered on-ramp firms operating through widgets or APIs embedded in unregistered crypto businesses. Its concern there was financial-promotions compliance, not the data risk I am describing. But the structure matters.

One party knows the identity. Another owns the interface. Another processes the payment. Another executes the crypto purchase. Another knows the destination wallet. Who owns the risk created by connecting them?

Regulation tends to follow activities and legal entities. Risk is less tidy.

For an embedded on-ramp relationship, I would want to know three things: Who can connect the customer to the wallet? Who can see enough activity to infer the customer’s holdings or wealth? Who can export or disclose the combined view?

Whatever the answers, linkage risk needs a named senior owner who can work across financial crime, privacy, cybersecurity and third-party risk. Partner reviews should consider not only whether each field needs to be shared, but what the recipient will know once it combines that field with everything it already has.

Almost No Risk – For Whom?

As I was finishing this column, Revolut CEO Nik Storonsky told the Financial Times that he wants to build a global bank with “effectively zero risk for the business.”

He was talking mainly about balance-sheet risk. Storonsky said he intends to keep lending exposure at roughly 10% to 20% of deposits, selling those loans on.

The quote stayed with me because it captures something about how the risk profile of a modern financial institution is changing. Storonsky is describing a model designed to carry little traditional balance-sheet risk for the bank itself. But it also becomes a critical crossroads between a customer’s real-world identity and their pseudonymous financial activity. That makes the information itself an exposure.

Ad for ChargebackX conference

ABOUT NOA SINGERMAN

Noa is a financial crime, fraud prevention and compliance leader with more than 12 years of experience across fintech, payments, crypto, intelligence and consulting. She has held senior roles spanning AML/CFT, fraud strategy, high-risk industry governance, merchant risk, transaction monitoring, financial investigations, asset tracing and value recovery.

At Fraudbeat, Noa writes about the intersection of compliance, financial crime and business and technology, and the decisions inside fast-growing companies that determine whether risk gets managed well or not at all.

View All Noa Singerman Latest Posts

Leave a comment

Your email address will not be published. Required fields are marked *