Revolut Leaked Customer Passports and Financial Data via Government Impersonation
The fintech giant handed over sensitive identity and transaction records to a threat actor using a legitimate government email domain.
Revolut has disclosed a data breach in which sensitive customer information was handed over to a threat actor impersonating a government agency. The incident highlights a critical failure in the company's verification process for legal information requests.
According to a Revolut spokesperson, the company identified a "sophisticated external impersonation scam" where an unauthorized third party used a legitimate government agency email domain to submit fraudulent requests for information. Believing these requests were authentic legal mandates, Revolut fulfilled them, inadvertently leaking a vast array of private data. The company has since blocked the email address involved and notified affected customers, regulators, and law enforcement.
The Scope of Exposed Data
The breach resulted in the exposure of comprehensive identity documents and financial records. Confirmed leaked data includes full names, dates of birth, occupations, phone numbers, and postal and email addresses. More critically, the attacker obtained copies of passports and driver's licenses, as well as verification selfies used for account authentication.
Financial disclosures were equally extensive. The leaked records included account statements featuring IBANs, account statuses, and wallet reference numbers. The threat actor also gained access to withdrawal records and full transaction histories, which specifically included Bitcoin activity.
Context of a Growing Giant
This security failure comes as Revolut continues its aggressive global expansion. With over 80 million customers, the fintech firm has recently entered markets in Mexico and India and received conditional approval for a national bank license in the United States.
However, this is not the first time the company has struggled with social engineering. In 2022, Revolut suffered a separate breach involving the manipulation of an employee. This latest incident underscores the persistent difficulty the firm faces in securing Know Your Customer (KYC) data against attackers who can mimic official authority.
Industry Implications
The breach demonstrates that domain authentication alone is an insufficient safeguard for validating government requests. By relying on the legitimacy of an email domain, Revolut created a vulnerability that allowed a threat actor to bypass standard security hurdles.
For the affected users, the combination of government-issued IDs and detailed cryptocurrency transaction histories creates a severe risk profile. Security experts warn that this specific dataset is highly valuable for targeted identity theft, extortion, and sophisticated phishing campaigns tailored to the users' financial habits.
What's Next
Revolut is currently working with regulators to assess the full impact of the leak. While the company has mitigated the immediate threat by blocking the attacker's email, the industry will be watching to see if the firm implements more rigorous, multi-channel verification for legal requests to prevent similar impersonation attacks in the future.