AUTO-UPDATED

Revolut handed customer passports to scammers using a real government email domain

Revolut inadvertently disclosed sensitive customer data to criminals after attackers used a legitimate government email domain to submit fraudulent information requests, bypassing standard security verification protocols.

Key Points

  • Attackers obtained personal data including dates of birth, postal addresses, phone numbers, and identity documents like passports and driving licenses.
  • Revolut confirmed the breach involved a sophisticated impersonation scam but stated that internal systems and customer funds remain secure.
  • The incident was first identified by crypto investigator ZachXBT, who noted that the fraudulent requests specifically targeted high-net-worth individuals.
  • Revolut has blocked the compromised email address, notified affected customers, and alerted relevant law enforcement and financial regulators.
  • The company has not disclosed the specific government agency involved, the number of affected users, or the duration of the unauthorized access.

Why it Matters

This incident highlights a critical vulnerability in how financial institutions process urgent data requests from government agencies, as attackers can exploit inherent trust in official domains. Because the exposed data includes permanent identity documents, affected customers face a long-term risk of sophisticated identity theft that cannot be mitigated by simply changing passwords.
The Next Web Published by Ana-Maria Stanciuc
Read original