Cybersecurity

Revolut gave scammers your passport — no hack needed, just a fake government email

Adrian Kessler

Revolut did not get hacked. No one breached its firewalls or found a vulnerability in its code. Instead, an attacker impersonated a government authority using an email address carrying a legitimate official domain, submitted a data disclosure request that Revolut’s verification checks accepted as genuine, and walked away with full identity documents, passport copies, onboarding selfies, and the complete account history of affected users — including every Bitcoin transaction on record.

The attack exploited a legal obligation, not a software flaw. Financial platforms are required by law to respond to official data requests from government bodies and law enforcement. By forging those requests convincingly enough to pass Revolut’s review, the attacker turned a compliance process designed to protect the public into the mechanism of a data theft. Revolut said it independently attempted to validate the request with the relevant authority, but the impersonation was discovered only after the data had already been shared.

For anyone whose account was included, the exposure is deeper than a standard breach. The stolen data ties full verified identities — legal names, dates of birth, home addresses, copies of passports or driver’s licences, and the selfies submitted during account verification — to Bitcoin wallet references and complete on-chain transaction records. That combination does not expire. Even if the affected users open new wallets, anyone with the leaked data can trace their prior coin movements to a confirmed real-world identity, permanently.

Revolut stated that no biometric facial telemetry was involved — the system-derived templates used for automated face-matching — only the raw photograph taken during onboarding. Customer funds were unaffected. The company blocked the fraudulent email address, notified the government authority whose identity was copied, alerted law enforcement, and filed the required regulatory disclosures. Whether European data protection regulators treat that response as adequate is an open question: the GDPR places strict obligations on how companies handle and protect the kind of identity documents that were taken.

The incident points to a category of attack that technical security alone cannot prevent. A company can encrypt its databases, audit its APIs, and run penetration tests — and still be socially engineered through the procedures it is legally required to follow. The problem is not Revolut’s code. It is the unresolved question of how any organisation verifies that a request bearing official markings actually originates from the official it claims to represent.

Revolut notified affected customers directly and has not disclosed the total number of accounts involved or the specific markets where exposure occurred. For anyone who received a breach notification, identity documents in the hands of scammers open the door to fraud extending well beyond the platform itself — fraudulent passport use, phishing calls referencing real account details, identity theft across financial services. And the Bitcoin record is a different kind of problem: Revolut can reset a password, but nobody resets the blockchain.

Tags: , , , ,

Discussion

There are 0 comments.