Skip to content

Revolut Handed Over Passports and Verification Selfies to a Fraudster Writing From a Genuine Government Domain: The Firm Will Not Say How Many Customers Are Affected

1 min read
Share
Revolut Handed Over Passports and Verification Selfies to a Fraudster Writing From a Genuine Government Domain: The Firm Will Not Say How Many Customers Are Affected

The British financial firm Revolut has confirmed it handed over customers' personal data to an unknown third party - because the request came from a genuine address at a genuine state institution. No database was breached, no system was broken into. Somebody wrote from a domain everybody trusts, and Revolut answered.

The list of what was handed over is long. Date of birth, home address, email, phone number, plus copies of identity documents - passports and driving licences. According to the notice the firm sent to affected customers, the package may also have included verification selfies, account statements and transaction history. In other words: everything you need to present yourself as somebody else to a bank.

A Revolut spokesperson described the case as "a sophisticated external impersonation fraud, in which an unauthorised third party used a legitimate government agency domain to submit fraudulent requests for information". The number affected? "Limited" - and not a single concrete figure. Nor which market is involved, nor which state agency was exploited. Only an assurance that customers' systems and money are untouched, which is true and at the same time beside the point: nobody steals the money the moment they get the documents.

Who was on the list

The crypto investigator known as ZachXBT was first to publish the contents of the message to customers and said the attack appears aimed at users with high balances. That is not a random fishing net - that is a selection. When somebody knows in advance whose documents they are asking for, the question is no longer only how they got in, but how they knew who to ask for.

Revolut says it blocked the address as soon as it discovered the fraud and that it notified the agency, the police and regulators. The firm has more than 80 million users worldwide and operates as a bank in over 30 countries; in recent months it obtained banking licences in France and Britain and conditional approval from the US regulator for a national bank, planned for the first half of 2027. At the same time it is preparing a stock market listing at a valuation of up to 200 billion dollars - almost three times the 75 billion from November.

The weak point is not technological

Here is what is worth remembering. Not one password fell, not one server was taken. What fell was the assumption that a request from a government domain is automatically a genuine request - procedure, not software. Banks in this region work on the same logic: a letter arrives with a letterhead, it gets answered. How many of them would recognise that the address is genuine but the person behind it is not?

The engineer who built the protection can be flawless, and the data still walks out through official correspondence because somebody read a domain and stopped checking. That is not fixed by another layer of encryption.