Skip to content

Invest1 publisher3 min readPublished

Revolut released passports and selfies to a request from a verified government domain

Revolut says its core systems were never touched, and that staff approved fraudulent information requests because the sender's domain was genuine and the email authentication valid. It is applying for a deposit-taking licence in Israel.

The Investor · Invest desk

Illustration accompanying Revolut released passports and selfies to a request from a verified government domain

What happened

  • Revolut has confirmed that an unauthorized party obtained sensitive customer records after sending fraudulent information requests from an email address on a genuine government-agency domain.
  • Affected customers were told the disclosed files could include passport or driving licence copies, onboarding verification selfies, addresses, occupations, account statements and complete transaction histories including Bitcoin activity.
  • The company says it blocked the address and alerted the relevant authority, law enforcement, data-protection bodies and financial regulators.
  • Files posted online included identity documents and verification selfies belonging to tennis player Alexander Shevchenko and Felix Roemer, chief executive of the online casino operator Gamdom, according to reporting that circulated on X.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint The sender's domain was real and its email authentication valid, so an email filter cannot close this hole. What has to change is which staff may release a passport scan on an inbound request, and what independent confirmation the requesting agency has to supply.
  • exposure Customers whose documents are out cannot reset them the way a password is reset, and the identity papers, live facial images, addresses and full payment histories together support identity theft and unusually convincing social engineering.
  • contradiction Revolut's framing and the customer's position diverge: crowdfundinsider.com argues that for a bank of this size the difference between a process failure and a network intrusion may matter less to users than the outcome.

Cost in an incident like this normally tracks the number of records. Independent researchers said the requests appeared aimed at high-net-worth users rather than a mass dump of the firm's entire customer base [9]. Revolut has described the number of people involved as limited [7]. Its notice to affected customers enumerates ten categories of data [6], ending with complete transaction histories including Bitcoin activity [5]. The selfie photographs went out, and Revolut has drawn a distinction between them and derived biometric templates, saying the templates were not involved [14]. The company did not name the agency whose domain was used, publish a customer count, or say whether the incident was confined to one country [8].

The financial stake is the Israeli licence application. Revolut already holds a local payment-services licence there and is seeking a "lean bank" licence from the Bank of Israel that would let it take deposits and extend credit [15]. Israeli officials have viewed a large international digital bank as a potential source of competition for the country's concentrated banking sector [17], and that view is the case for granting it. The same application puts the firm's handling of official data requests in front of a supervisor. Full banking operations have not started, though thousands of Israelis living or previously living abroad may already hold accounts opened elsewhere [16].

On Telegram, the attackers said they would keep releasing more records every day until Revolut "pays for leaking their customers" [12]. They have also accused the company of negligence and of handing data to parties outside its proper jurisdiction, and have threatened to publish further details about how internal teams handled the requests [13].

Three outcomes are consistent with what is on the record. The Bank of Israel can treat a disclosure failure as material to a licence that would let Revolut hold retail deposits, and the timetable slips. Or the supervisor reads the episode as a fraud committed against Revolut, notes that customer funds were unaffected [4], and the application proceeds on its merits. Or the daily releases stop within a week because the set was small to begin with; Revolut's own description of a limited group implies as much [7].

I think the larger number is on the licence. Revolut serves tens of millions of customers across dozens of markets [19]. A targeted disclosure covering a limited group [7] is a smaller bill than a delay to the one permission that converts a payments business into a funded balance sheet [15]. An affected-customer figure in the thousands would make direct remediation the bigger cost. And a lean bank licence granted without any public regulatory comment on the incident would show the supervisor never treated the disclosure process as part of the test.

What to watch

  • Any Bank of Israel decision or public comment on Revolut's lean bank licence application.
  • A published count of affected customers, whether from Revolut or a data-protection authority.
  • Whether the attackers' daily releases continue past this week. That is a test of the "limited" description.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories