Revolut handed customer passports to scammers using a real government email domain

Credit: Shootdiem via Shutterstock.com Revolut gave sensitive customer information to criminals who requested it from what appeared to be a government email address, and did so because the address was real. The company has confirmed the breach and says its systems were never touched; the story was reported by TechCrunch on Friday. A Revolut spokesperson told TechCrunch the company had “identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information”, and added that “Revolut systems and customer funds are unaffected”. What went out is what matters.

Dates of birth, postal addresses, email addresses and phone numbers, plus identity documents including passports and driving licences. TechCrunch reports that verification selfies, account statements and transaction histories may also have been disclosed. That is close to everything a person would need to impersonate a Revolut customer somewhere else, and unlike a password it cannot be changed. Banks receive requests from police forces and government agencies as a matter of routine, sometimes urgently, and staff are trained to treat them as legitimate.

An attacker who can send from a genuine government domain skips every check that a forged letterhead would fail. It is a known weakness in how law enforcement asks companies for data, and it works because the alternative, treating every official request as suspect, is not something a bank wants to be caught doing either. Revolut says it blocked the address once it worked out what was happening, told the customers involved, alerted the government agency whose domain was used, and contacted law enforcement and financial regulators. It will not say how many people were affected beyond “limited”, and it has not named the markets.

Also, it has not said which agency’s domain was abused, how the attackers got access to it, how long the requests went on before anyone noticed, or whether the agency itself had been compromised. The breach surfaced through the crypto investigator ZachXBT, who posted about it on Friday and said it had targeted high-net-worth individuals. We have not independently verified that characterisation, but it sits awkwardly beside what Revolut has been building. The company launched a private bank with a £500,000 entry threshold, aimed squarely at exactly those customers, as part of a push towards a $200bn listing.

Scale is what makes this more than an unlucky week. Revolut reached a $115bn valuation this year, holds banking licences in the UK and France, and has said its IPO is two years off. It has also already been told once, by the European Central Bank, to slow its product launches. There is a clock running on the paperwork, too. European data protection rules give a company 72 hours from becoming aware of a personal data breach to notify its supervisory authority, and require it to tell the individuals affected directly where the risk to them is high, and the company says it has done both.

What the rules do not require is telling everyone else, which is why the public account of this is currently a sentence from a spokesperson and a post from an investigator. Customers who were contacted should treat the exposed material as permanently public. The practical risk is not someone emptying an account, which Revolut says has not happened, but the slower kind: identity documents and a verified selfie are the raw material for opening credit somewhere else, or for a convincing approach from someone who already knows your address, your phone number and what you spend. None of this required breaking into anything.

No malware, no stolen credentials, no clever exploit. Someone wrote emails from an address that people were trained to trust, and one of Europe’s largest banks answered them. That is the uncomfortable part, and it is not a problem Revolut can fix alone, because the trust being exploited belongs to governments rather than to banks.

Leave a Reply

Your email address will not be published. Required fields are marked *