Revolut Gave Scammers Customer Passports via Fake Government Emails

Scammers used a real government agency email domain to trick Revolut staff into handing over passports, selfies, and transaction records

Nikshep Myle Avatar
Nikshep Myle Avatar

By

Image: Wikimedia Commons – Boubloub

Key Takeaways

Key Takeaways

  • Scammers exploited a real government email domain to trick Revolut staff into releasing customer data.
  • Exposed passports and biometric selfies enable long-term identity fraud at other financial institutions.
  • Revolut withheld key details, including the number of customers affected and the misused agency’s identity.

Revolut has confirmed it disclosed passport copies, verification selfies, and full transaction histories to an unauthorised third party, leaving confidential files exposed through a process failure rather than a server breach. No one breached its servers: scammers sent emails from a real government agency domain, Revolut’s staff processed them as legitimate legal demands, and the data left the building.

This was not a technical failure. It was a process failure, and the mechanism that failed is one that every regulated financial institution relies on daily.

What Was Exposed

The leaked bundle contained almost everything needed to impersonate an affected customer at another institution.

According to notification emails reviewed by TechCrunch, the disclosed data included birth dates, home addresses, phone numbers, and email addresses, as well as copies of passports and driving licences. Verification selfies were reported as possible but not confirmed for every customer. Account statements and transaction histories, including Bitcoin and crypto records, were also disclosed, along with IBANs and account opening dates for some customers. The scope of this database leak means affected customers face risks well beyond the immediate incident.

Revolut confirmed that login credentials, card PINs, and passcodes were not part of the disclosed bundle. The company also reports no evidence of direct account takeover.

How It Happened

The attack required no technical exploit, only a real government email address and Revolut’s trained compliance response.

A Revolut spokesperson described the incident as “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” according to TechCrunch on September 12, 2026.

Banks and fintechs are procedurally conditioned to respond promptly to law-enforcement data requests. Questioning those requests creates legal and political friction, and that conditioned trust became the attack surface. The tactics share similarities with how a surveillance app can exploit institutional trust to extract sensitive information.

How the attackers obtained the ability to send from a real government domain remains unclear. Revolut has cited an ongoing investigation and declined to name the agency involved.

What Revolut Says It Did

Revolut says it acted quickly once the scam was identified, but significant details remain undisclosed.

After identifying the impersonation scam, Revolut blocked the fraudulent sender, notified the relevant government agency, law enforcement, and financial regulators, and contacted affected customers directly. The company says it has complied with GDPR’s 72-hour breach notification requirements to supervisory authorities.

What Revolut has not disclosed: the exact number of customers affected, which markets were involved, which government agency’s domain was misused, and how long the fraudulent requests continued before detection.

Who Was Targeted

The claim that wealthy customers were specifically targeted has not been independently confirmed.

On-chain investigator ZachXBT brought the incident to wider attention by posting about notification emails sent to affected customers, characterising the targets as high-net-worth individuals. That assessment has not been independently verified, and Revolut has not confirmed it.

Revolut recently launched private banking services for customers holding balances around £500,000 and is pursuing a large IPO, making a data incident of this nature particularly sensitive at this moment.

The Longer Risk

Passport copies and biometric selfies cannot be rotated like passwords, and the risk is long-tail rather than immediate.

Unlike stolen passwords, leaked identity documents and facial images cannot simply be changed. Attackers who compromise password vaults face a recoverable problem, but stolen biometric and document data creates permanent exposure. Attackers can open credit lines at other institutions, execute SIM-swap attacks, or run targeted social engineering using the real transaction details they now hold.

Analysts note this is a systemic problem that email authentication alone cannot solve. A sender operating from a legitimate government domain will pass every standard verification check.

If You Were Affected

Treat exposed documents as permanently compromised and act on the long-tail risks, not just the immediate ones.

If Revolut notified you, the following steps are worth taking now:

  • Treat exposed identity documents as permanently compromised; consider replacing passports or driving licences based on your risk assessment and local replacement process
  • Enable a PIN or port-out lock with your phone carrier to reduce SIM-swap exposure
  • Monitor credit reports for unusual account openings or inquiries
  • Verify any contact claiming to be from Revolut, tax authorities, or law enforcement independently through official in-app support, not by responding to emails or calls that reference your transaction history

This incident adds pressure on governments and financial institutions to move beyond email for lawful data requests, toward secure portals or certificate-backed digital signatures that a fraudster controlling an inbox cannot replicate.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →