Revolut Leaks Passports and IDs After Falling for Government Impersonation Scam
The fintech giant disclosed sensitive customer data after scammers used a legitimate government email domain to deceive the company.
Revolut has confirmed a data breach that exposed sensitive customer information to unauthorized third parties. The leak occurred after the fintech company fell victim to a sophisticated impersonation scam involving fraudulent requests for data.
According to a Revolut spokesperson, an unauthorized party utilized a legitimate government agency email domain to submit fraudulent requests for information. In response, Revolut handed over sensitive data, including customer birth dates, phone numbers, postal and email addresses, and copies of identity documents such as driver's licenses and passports. The company has since blocked the email address used in the attack and notified regulators, law enforcement, and the affected customers.
The Scale of the Risk
Revolut operates as a global fintech powerhouse with more than 80 million customers. The company is currently in a phase of aggressive international expansion, growing its footprint in the UAE, Mexico, and India. More critically, Revolut recently received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank within the United States. This regulatory milestone comes as the company is reportedly weighing a public listing that could see its valuation reach $200 billion.
Why It Matters
This incident exposes a critical vulnerability in the verification protocols that major financial institutions use to handle government data requests. The fact that a legitimate government domain was leveraged for social engineering demonstrates that traditional domain verification is no longer a sufficient safeguard against sophisticated actors.
For a firm seeking a massive IPO and navigating the stringent requirements of the U.S. banking system, the loss of high-stakes identity documents—such as passports—poses significant reputational and regulatory risks. Such lapses can invite increased scrutiny from financial watchdogs regarding the company's internal security controls and its ability to protect customer privacy at scale.
What's Next
While Revolut has taken immediate steps to block the fraudulent source, the long-term impact on its U.S. banking ambitions remains to be seen. Observers will be watching for whether regulators demand a comprehensive audit of the company's data-sharing workflows. It also remains to be fully detailed exactly how many customers were impacted and whether the attackers successfully leveraged the stolen identity documents for further fraud.