Revolut handed over customer passports and selfies after a fake government email
Revolut confirms customer data breach through fake government requests

Revolut confirmed it disclosed sensitive customer data — birth dates, addresses, phone numbers, passports, driver's licenses, and possibly verification selfies and transaction histories — to an unauthorized third party that used a legitimate government agency email domain to send fraudulent information requests. The fintech said a limited number of customers were affected, blocked the address, and alerted regulators and law enforcement. It declined to say how many people were impacted or which agency was impersonated.
Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.
- neither_color
I had an interesting experience with my Revolut card. I only top it up when traveling, and the rest of the time it sits nearly empty, with like $3-4. At some point I started getting occasional notifications about transactions declining. Stuff like video game points and random little online shops. Clearly my card's been skimmed or otherwise leaked somehow. Bummer.
Since Im months away from my next trip I didnt immediately cancel the card and just left it on out of curiosity. I started blocking every attempted merchant. At some point, I started getting Netflix subscription attempts, and when I tried to block it, it said "We can't block payments to Netflix. If you have a subscription with them, you can cancel it directly." Makes me wonder what kind of rube goldberg machine their backend runs on.
- hndhyc0bdt
Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.
- rawland
How can this happen to a modern fintech... Esp. handling identity verification so poorly?
> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
- tdrz
Here is one of the replies I got during my conversation with their agent (unsure if human or automated):
"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."
This was in the same conversation where I sent them the article.
- codedokode
This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.
- janandonly
Storing identification data (like a scanned passport) is not necessary. The question is “did you check the customer identity?” And if the answer is Yes, then you can mark it as such. You don’t need to store these scans at all.
- autotune
I lost access to my Revolut account a while back and recovery did not work after losing access to my primary email address and MFA. They also removed the ability to deposit checks on their mobile app. For these reasons I can not treat it like a real bank anymore as much as I love their 4% APY savings account rate. Unlike gmail, which had recovery options with a secondary email address. They could have implemented something similar.
- hrpnk
Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?