in

Revolut Handed Over Passports and Transaction Histories to a Fake Government Email

Revolut has confirmed that it released sensitive customer records, including copies of passports and driving licences, identity verification selfies, account statements and full transaction histories, to an unauthorised third party who emailed the company from a real government agency’s own domain. The London fintech says its own systems were never compromised and that customer funds are unaffected. It has not said how many customers were hit, which market they were in, or which agency’s domain the fraudster used.

How a fraudulent request cleared Revolut’s checks

The attacker did not break into anything. They sent what looked like an official data request from an email address on a legitimate government agency domain, and because the message carried valid domain authentication, Revolut’s team treated it as genuine and fulfilled it.

Hosting 75% off

“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” a company spokesperson told TechCrunch, which reviewed the notification emailed to affected customers. Revolut says it blocked the email address once it identified the scam, and alerted the relevant government agency, law enforcement and financial regulators.

Banks and fintechs receive genuine law enforcement and regulatory data requests constantly, and the process is largely manual and email-based. That is the weakness the attacker used. Emergency and official data request fraud has hit large US platforms before, but a request arriving from inside a real government domain, rather than a lookalike one, defeats the usual spelling check that staff are trained to run.

What was in the file

According to the customer notification, the disclosed information included names, dates of birth, postal and email addresses and phone numbers, along with copies of identity documents such as passports and driving licences. Revolut said the data may also have included verification selfies, account statements and transaction histories. Reporting by BleepingComputer noted the statements carried IBANs, account opening dates and withdrawal records.

Crypto investigator ZachXBT, who published the notification late on Friday, said the incident looked targeted at high net worth users rather than random accounts. Revolut described the number of affected customers only as “limited” and declined to give a figure.

A stolen document set is permanent in a way a password is not

Change a leaked password and the problem ends. A passport scan paired with the selfie you took holding it cannot be reissued on a Tuesday afternoon, and that exact pair is what most platforms accept as proof that you are you.

For readers running cross-border freelance income, that is the part worth sitting with. The same passport copy and selfie usually sit inside a Payoneer account, a Wise account, an Upwork or Fiverr identity check, a crypto exchange and a local bank file. Anyone holding that set has what they need to pass a human reviewer on a different platform entirely, or to open an account in someone else’s name. We looked at how thin the margins already are on these rails in our piece on JazzCash crossing 60 million users as Payoneer raised its fee.

Practical steps if you hold a Revolut account: check whether you received a notification directly from Revolut rather than acting on any email that claims to be about the incident, treat any call or message that quotes your real account details as hostile until proven otherwise, move every financial account you own to app-based or hardware two factor authentication rather than SMS, and ask your payment platforms what their process is for flagging compromised identity documents. Revolut has said funds are not affected, so the exposure here is identity, not balance.

The questions Revolut has left open

Three gaps stand out. The company has not published a customer count, has not named the agency whose domain was abused, and has not said whether the request was limited to one market. Scale matters because Revolut states on its own About page that it serves more than 80 million customers and operates as a bank in more than 30 countries, so “limited” covers an enormous range.

Timing sharpens it further. Revolut received conditional approval from the US Office of the Comptroller of the Currency earlier this month to establish a national bank, and has been reported as weighing a listing at a valuation far above its private mark. Regulators in the UK and EU have been notified, which means the eventual public record on this incident is likely to come from a supervisory body rather than from the company.

Hosting 75% off

Logo Design Grew 44% on Upwork While AI Image Tools Grew 95%: What Clients Are Really Buying

Apple Ships iOS 27 and Siri AI, but Not in Urdu, Arabic or Hindi