Markets by Trading view

Revolut Handed Passports and Account Histories to a Fake Government Request

Facebook
Twitter
LinkedIn

Revolut has confirmed it released sensitive customer files after treating fraudulent information requests as genuine government demands.

The requests came from an email account on a legitimate government agency domain and carried valid authentication. Revolut fulfilled them on that basis. It later contacted the agency, decided the requests were not authentic, blocked the address and began notifying customers.

A spokesperson told TechCrunch the episode was “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” Revolut says its systems and customer funds are unaffected. This was not an intrusion into core banking systems. It was a failure of legal-request controls.

On-chain investigator ZachXBT circulated the customer notice on Friday. Several users received the alert the same day.

According to that notice, the disclosed material may have included full name, date of birth and occupation; home address, email and phone number; copies of a passport and/or driving licence plus the verification selfie taken at onboarding; and account statements, IBAN, withdrawal records and full transaction history, including Bitcoin activity.

Revolut says biometric facial telemetry was not disclosed. Passwords, card PINs and crypto private keys are not described as having left. No customer funds have been reported missing.

Revolut has not published a headcount. A spokesperson told TechCrunch that a limited number of customers were affected and that those customers were contacted directly. It has not named the market or the government agency, citing a live investigation. ZachXBT’s reading is that the incident looks small and aimed at high-net-worth users. That is an investigator’s view, not a company figure. Revolut says it has alerted the agency, law enforcement, data protection authorities and financial regulators.

Most large leaks start with stolen credentials or a weak database. This one started with a mailbox that cleared the checks a compliance team is trained to trust: official domain, valid authentication, the look of a lawful demand.

The file that went out is the issue. A passport, a home address and a full payment history is enough to build a targeted fraud pack. Where Bitcoin activity sat on the same statement, a recipient can try to join a legal identity to an on-chain trail.

Revolut has more than 80 million customers and bank permissions in more than 30 countries. The open questions for a risk committee are unchanged: how many files, which legal entity, which agency domain, how an unauthorised mailbox sat on that domain, and whether a second check exists before KYC packs leave the building.

Those answers are not in the public notice.

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Related Posts

Write your email to verify subscription

Loading...

Sign up for our free newsletter and receive the latest banking and fintech stories, straight to your inbox - every week