Revolut leaks customer IDs after falling for government impersonation scam
The British neobank handed over identity documents and transaction histories to attackers using a genuine government email domain.
Revolut has confirmed a significant data breach after employees were deceived into handing over sensitive customer information to attackers. The incident underscores a critical failure in internal verification protocols at one of the world's largest neobanks.
According to the company, the breach was the result of a "sophisticated external impersonation scam." Attackers successfully tricked Revolut staff by using a genuine government email domain to request customer data, bypassing standard security checks. The exposed information is extensive, including dates of birth, postal addresses, email addresses, and phone numbers. More critically, the leak includes copies of identity documents such as passports and driving licenses, as well as verification selfies, account statements, and full transaction histories.
The Scale of the Risk
Revolut currently serves over 80 million customers globally, making the potential blast radius of this breach substantial. The nature of the stolen data—specifically the combination of government IDs and verification selfies—creates a high risk of identity theft and synthetic fraud for the affected users. While the company has notified those impacted, the permanent nature of leaked identity documents means the risk to these customers persists long after the initial breach is contained.
Market and Regulatory Pressure
This security lapse arrives at a precarious moment for the British fintech giant. Revolut is reportedly targeting a valuation of up to $200 billion for a potential initial public offering (IPO), a massive leap from its previous private valuation of $75 billion. Such a high-profile failure in data handling is likely to invite intense regulatory scrutiny regarding the firm's data protection protocols and internal governance. For potential investors, the incident raises questions about whether the company's rapid global expansion has outpaced its operational security and compliance frameworks.
What's Next
Revolut has not yet detailed the specific internal failures that allowed a spoofed or compromised government domain to trigger a data release. Industry analysts will be watching for whether the company implements more stringent multi-factor verification for data requests from external agencies. Additionally, while third-party reports have suggested ransom demands and the targeting of high-net-worth individuals, Revolut has not officially confirmed these details. The company's ability to maintain investor confidence ahead of its IPO will depend on its transparency regarding the full scope of the leak and the concrete steps taken to prevent a recurrence.