SecurityPrivacy Revolut

Revolut gave out customer passports to a spoofed government email

Illustration for the Revolut spoofed government request story

Nobody broke into Revolut. Someone sent an email from the right domain, and the documents went out through the front door.

What was disclosed

Revolut confirmed it released customer data after complying with what it took to be a genuine government demand. The request came from an unauthorised account on the agency’s official domain and carried valid domain authentication, which meant it passed the technical checks a receiving system is built to make.

The disclosed material covered full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers, along with passport or driving licence copies, verification selfies, account statements, IBANs, withdrawal records and full transaction histories including Bitcoin activity. The exposure appears limited and aimed at higher-net-worth customers. Revolut says funds are safe, and it has not named the agency involved.

The control with no owner

No code failed here. Encryption held, the platform was not breached, and every control with an owner did its job. What was missing was the step that asks whether the party requesting a customer’s identity documents has any authority to receive them, which is a process question rather than an engineering one.

That gap sits behind most law-enforcement-request data leaks across fintech platforms, and it is unusually costly in this case because of what was released. A password can be rotated after a breach. A passport scan and a verification selfie are the customer’s permanent identity documents, and once they are out, the elevated phishing risk Revolut acknowledges does not expire.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.