Skip to content

Product1 publisher3 min readPublished

Revolut handed over passport scans to fraudulent requests sent from a real government domain

Revolut says an impersonation scam used a legitimate government agency domain to ask for customer records, and the fix it has described is blocking one email address. It has not said how many customers were affected.

The Product Desk · Product desk

Photograph accompanying Revolut handed over passport scans to fraudulent requests sent from a real government domain
Photo: techcrunch.com

What happened

  • A Revolut spokesperson said a "limited" number of customers were affected and had been contacted directly, and the company declined to give a figure or name the agency whose domain was used.
  • Revolut said it blocked the email address, alerted the agency, law enforcement and regulators, and that its systems and customer funds are unaffected.
  • Crypto security researcher ZachXBT published Revolut's customer notice late on Friday and said the incident appeared to have been targeted at high net worth users.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • exposure Affected customers carry this one indefinitely. An address or a phone number can be changed, and a passport image already delivered to a stranger, alongside the selfie taken to verify it, cannot be recalled or reissued.
  • constraint The only control Revolut has described operates on a single sender. Any team that treats a genuine agency domain as proof of identity is in the position it was in last week.
  • decision Every firm with a legal request inbox now has to pick a verification standard it can defend to a regulator, because Revolut's own account puts the failure in the check on the requester.
  • precedent Revolut goes into its US national bank build-out with this case in the public record while the OCC approval is still conditional.

A request for customer records arrived from a government agency's real email domain, and Revolut answered it. The company's account of what happened is one sentence. "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the spokesperson said [5]. Revolut did not say whether the agency's mailbox was compromised or the address was spoofed [13].

The remedy on the record is address-level. Revolut said it blocked the email address, alerted the relevant government agency, law enforcement and relevant regulators, and that "Revolut systems and customer funds are unaffected" [6]. All of that can be true and still leave the person who staffs a legal request queue on Monday with nothing new to work with.

The notification to customers, which TechCrunch reviewed, lists birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver's licenses [2]. Revolut said the data may also have included verification selfies, account statements and transaction histories [3]. A phone number can be changed in an afternoon. A passport image sitting next to the selfie taken to verify it is the exact bundle someone needs to pass as that customer somewhere else. ZachXBT, the crypto security researcher who published Revolut's customer email late on Friday, said the incident appeared to have been targeted at high net worth users [8].

"Limited" is the only quantity Revolut has attached to the incident [4], set against more than 80 million customers and bank operations in more than 30 countries [7]. If the targeting ZachXBT described holds up, the selection matters more than the size: a handful of deliberately chosen wealthy account holders is a worse outcome than a random sample of the same count.

Teams tell themselves an inbound request has been verified because it came in on an official channel. A sender domain proves the sender controlled a mailbox at that domain. A more useful sort for a request desk runs on two axes: whether the requester was confirmed on a route they did not choose, and whether the data being released can be reissued. Passwords and account numbers can be. Passport scans, verification selfies and transaction histories cannot. Anything in the second group should not move on a sender domain alone. The control is a callback to a number the agency itself publishes: it costs turnaround time in the queue, and it takes the decision off whichever reviewer happens to open the email.

Revolut received conditional approval from the U.S. Office of the Comptroller of the Currency earlier this month to set up a national bank, which it expects to launch in the first half of 2027 [9]. It is also reported to be weighing a listing that could value it at as much as $200 billion, against the $75 billion private valuation it carried in November [10], roughly 2.7 times the November figure [11].

What to watch

  • Whether the government agency whose domain was used is identified, and whether other banks report requests from the same address.
  • Whether a regulator opens a formal inquiry that forces Revolut to publish a count of affected customers.
  • Whether the OCC's conditions on Revolut's national bank approval touch how it authenticates law-enforcement and agency data requests.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories