Sep 15 / Latest News

Revolut Discloses Passport and ID Data After Fraudsters Use Real Government Email Domain to Request Customer Records

Revolut has confirmed that sensitive customer information was disclosed after fraudsters used a legitimate government agency email domain to submit fraudulent data requests, allowing the attackers to obtain identity documents and account details under the guise of official inquiries.

In notifications sent to affected customers and reported by TechCrunch, the fintech company said the incident exposed birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports, driver’s licenses, and facial verification images. Crypto fraud investigator ZachXBT said on Telegram that account statements, IBANs, and transaction histories were also accessed, adding that the breach appeared to target high‑net‑worth users.

Revolut described the number of affected customers as “limited,” but acknowledged that the attackers successfully impersonated a government agency by using an email domain with valid technical authentication. Because the requests passed standard domain checks, Revolut processed them as routine legal compliance inquiries.

“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” a spokesperson said. The company blocked the email address and notified regulators and law enforcement. Revolut emphasized that its internal systems and customer funds were not compromised.

The incident is particularly sensitive for Revolut, which recently secured long‑awaited banking licenses in both the United Kingdom and the European Union after addressing regulatory concerns around compliance and operational controls. The breach highlights how attackers increasingly exploit trusted communication channels rather than attempting to break through hardened technical defenses.

Jake Moore, global cybersecurity advisor at ESET, said the scam demonstrates how difficult such attacks are to detect. “What makes this particularly worrying is that the requests came from a legitimate government email account, making them far harder to spot as a phishing email. The threat actors were able to cleverly disguise themselves as a genuine organisation and simply request the information from Revolut.”

Moore added that cybercriminals often bypass direct attacks on a target’s infrastructure by impersonating trusted sources instead. “Increasingly, cybercriminals don’t need to break through the technical security controls of a final target if they can impersonate a trusted source.”