Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor posing as government entity

Revolut appears to have exposed personally identifiable information (PII) for a subset of users due to failing to detect a fraudulent government request.

Exposed data included:

  • Copy of passport and/or driver's licence, plus the verification selfie
  • Account statements, IBAN, withdrawal records, and full transaction history including Bitcoin
  • Full name, date of birth, occupation
  • Home address, email, phone number

While the incident is likely limited in size it seems to have been targeted at high net worth users. 

An email alerting users was sent out to multiple Revolut users yesterday.

Source: ZachXBT.

61 points · 7 comments · view on lemmy.world

7 Comments

twinnie@feddit.uk · 13 pts · 5h

They’ve been nagging me for months to upload documentation. I think I’ll just close it instead.

Kyrgizion@lemmy.world · 8 pts · 5h

So far, I haven't had to ID verify for anything. The moment I do it's immediately over. I will live like a 1700's hermit before I'll permit it.

SolacefromSilence@fedia.io · 7 pts · 3h

Better to not collect such information in the first place, then it can't be sold, stolen, or leaked.

Eyekaytee@aussie.zone · 5 pts · 5h (2 replies)

Anybody else wondering which governments email server got hacked?

manualoverride@lemmy.world · 1 pts · 4h (1 reply)

The government server would not need to be hacked, you can spoof an email address, and they’re not going to be emailing them back with this much data. They most likely got them to upload to a file transfer system.

Eyekaytee@aussie.zone · 5 pts · 3h

you can spoof an email address

That would fail SPF and DKIM so unlikely to get past even a basic email gateway these days

The request originated from an unauthorized email account created directly within an official government authority’s domain infrastructure. The communication carried genuine domain authentication credentials leading Revolut to fulfill the request under the reasonable belief that it was an authentic government agency request.

Once we became aware of the issue, we independently contacted the relevant government agency to validate the request, ultimately alerting the authority to the unauthorized account apparently operating within their domain

https://thecybersecguru.com/news/revolut-data-breach-2026/

chicken@lemmy.dbzer0.com · 2 pts · 7m

I blame KYC/AML laws