bytevyte
bytevyte
Language
quick-beats

Revolut Data Breach: Fake Government Email Cleared Checks, Exposing Passports and Bitcoin Records

Revolut data breach

Revolut confirmed a data breach that exposed passport copies, verification selfies and full transaction histories for a limited set of customers, after the company acted on fraudulent requests sent from an email address inside a real government agency's domain. Reuters and Yahoo Finance reported the confirmation. Revolut said balances and internal systems were not touched.

The breach was confirmed publicly on September 12, a day after notification emails began reaching affected account holders, according to those reports. Revolut's notice to customers listed identity documents, dates of birth, postal and email addresses, phone numbers and IBANs among the data disclosed, along with Bitcoin transaction activity.

The request carried valid domain authentication credentials, so it passed the checks normally used to confirm that a message originates from the domain it claims, Reuters and Yahoo Finance reported. Revolut identified the address as unauthorized only after the records had been supplied. It then blocked the address and alerted the government agency involved, law enforcement, data protection authorities and financial regulators.

What the breach exposed, and what it did not

The customer notice separates the material disclosed from the data Revolut says stayed private, as reported by Reuters and Yahoo Finance. That split matters more than the reassurance about balances, because the two categories carry different risks.

Data categoryStatus in Revolut's customer notice
Identity documents (passports, driving licences)Disclosed
Verification selfiesDisclosed
Names, dates of birth, occupations, home and postal addresses, email addresses, phone numbersDisclosed
IBANs and account detailsDisclosed
Full transaction histories, including Bitcoin activityDisclosed
Passcodes, login details, PINs and private keysNot exposed
Customer balances and Revolut's internal systemsUnaffected

Revolut has not named the agency whose domain was used, disclosed how many customers were affected, or said how long the fraudulent account had access, the reports said. It has also not explained why the request was fulfilled without confirmation through a second, independent channel.

Identity verification was the entry point

Nothing in the incident involved breaking encryption or penetrating payment rails, based on the reported account. The attacker borrowed the authority of a government domain and let Revolut's own compliance process do the work. Anti-money-laundering rules oblige regulated firms to collect and retain identity documents, and the same obligation creates a legitimate channel for authorities to request them. Impersonating that channel needs no malware and no insider.

No customer action set this in motion. Nobody clicked a link, entered a password or approved a payment, according to Reuters and Yahoo Finance. The records moved through a routine institutional process, so the standard advice about suspicious messages does nothing to lower the risk here. Affected account holders learned about the disclosure from Revolut.

That is why the reassurance about untouched funds covers the smaller half of the problem. A stolen balance can be reversed or reimbursed. A passport scan, a verification selfie and a date of birth cannot be reissued as a set, and they are the raw material for opening accounts, clearing identity checks and taking over other services in the victim's name.

The Bitcoin histories widen the exposure further. Matching an identity document to a wallet's transaction record ties a verified real person to on-chain activity that is otherwise pseudonymous, and that link stays on the ledger permanently. Revolut has described the episode as a sophisticated external impersonation scam, which places the failure at the verification step rather than in its banking stack.

The asymmetry is what makes this class of breach costly for a fintech. A payment fraud loss is bounded by the balance involved and is often recovered by the bank. The documents in question are held because a regulator required them. Their value to an attacker does not decay when the account is closed.

Verifying a request through a separate channel is the usual defence against impersonation, and it is also the step that sits awkwardly against how agency requests arrive. Investigators working to a deadline expect fast turnarounds, and every callback adds delay. Firms weighing speed against verification end up with the trade-off this incident exposed, and the cost of getting it wrong lands on the customer whose passport was in the file.

The regulatory arithmetic

Revolut's handling runs along several tracks at once. Under UK and EU data protection rules, a personal data breach that puts people's rights at risk must be reported to the relevant supervisory authority within 72 hours of discovery, and the individuals concerned must be told without undue delay when the risk is high. Identity documents and verification selfies sit at the high end of that scale.

Revolut's description of the affected group as very limited carries weight in its public messaging. Notification duties do not attach a minimum size; the test turns on the risk to the individuals involved, and the customers who received notices are identified by name in them.

The company is also pursuing a UK banking licence, and scrutiny of operational resilience and financial crime controls is at its heaviest during that process. A breach that turned on a verification failure rather than a technical one lands on the controls examiners assess.

The open question is procedural. Banks and fintechs commonly require law enforcement and agency requests to be confirmed through a second channel before customer records move. Revolut has not said whether that step exists in its workflow, whether it was skipped, or whether the request arrived through a route that bypassed it. Until it does, the disclosure stays outside the scope of what a balance reassurance covers.

Why this matters

The breach shows that the strongest lock in consumer finance is no longer the one around the vault. A lost balance is recoverable; a passport scan paired with a matching selfie is not, and that is the combination the affected customers now live with. So long as regulated firms must collect and keep identity documents to satisfy anti-money-laundering rules, requests that ask for those documents will stay worth impersonating. The test will be whether firms change how they verify who is asking.

Photo by Julian Gojani on Unsplash

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.