Revolut handed customer passports and selfies to a scammer with a real-looking government email
The fintech says it fulfilled an information request that arrived from a genuine-looking government domain, exposing IDs, selfies and full transaction histories of what it calls a very limited number of customers.

Key points
- Revolut, a fintech serving more than 80 million customers across 160-plus countries, has told affected users it handed over personal data to a scammer posing as a government agency.
- The request arrived from an email address on the real agency's domain and carried valid domain authentication, so Revolut's staff treated it as genuine.
- Data given up includes full names, dates of birth, home addresses, passport and driver's licence copies, selfies used for identity checks, IBANs and complete transaction history including Bitcoin activity.
- Revolut says customer funds and its systems were not touched, and the number affected is very limited, though it has not published a figure.
- Crypto investigator ZachXBT said the targeting appears to focus on high net worth users, first reported by BleepingComputer.
Revolut, the London-based digital bank used by more than 80 million people, has admitted it sent sensitive customer files to a criminal who pretended to be a government agency over email.
The request looked legitimate. It came from an email address on the real agency's own domain, and it passed the automatic checks email servers use to spot forgeries. Revolut staff, believing it was a genuine legal request, sent the data.
That is a bad day at any bank. It is a worse day when the data includes passport scans and the selfies customers took to prove their identity when they opened the account.
What did the scammers actually get?
A lot. Revolut's notice to affected customers lists identity details (full name, date of birth, occupation), contact details (postal address, email, phone), copies of identity documents such as passports or driver's licences, and the facial verification selfies taken during Know Your Customer sign-up, the checks banks run to confirm a new customer is who they say they are.
The leak also covers account statements with IBANs, the international bank account numbers used for transfers, along with withdrawal records and the full transaction history, Bitcoin movements included.
That combination is unusually toxic. A criminal now has enough to impersonate the victim to another bank, to open crypto exchange accounts in their name, or to target them directly knowing exactly how much money they hold and where it goes.
How did the hackers pull it off?
They abused trust in email, not a flaw in Revolut's app. According to Revolut, the message came from "an unauthorised email account sent directly using the official government agency's email domain" and "carried valid domain authentication credentials."
In plain English, the sending address really was on the agency's domain, and the anti-spoofing checks that email servers run (the standards known as SPF, DKIM and DMARC) came back clean. Either the criminal had access to a mailbox inside that agency, or the agency's mail setup let an outsider send as one of its addresses.
This is an authentication problem, proving who sent the mail, being confused for an authorisation problem, deciding what that sender is allowed to ask for. The domain check told Revolut the email was really from the agency. It did not, and could not, tell Revolut whether the person behind the keyboard had any right to demand customer records.
Who is affected and what should they do?
Revolut told Reuters the breach hits a "very limited" number of customers but has not published a figure. Crypto fraud investigator ZachXBT said over the weekend that the attack "seems to have been targeted at high net worth users."
If you get a notification from Revolut, assume the criminal knows your address, your ID document number and what your face looks like on your passport. Treat unexpected calls or emails claiming to be from Revolut, HMRC, the police or a crypto exchange with suspicion, especially any that ask you to move money or confirm a code. Multi-factor authentication on your Revolut account and on any linked email will not undo this leak, but it makes account takeover much harder from here.
This is Revolut's second disclosed breach. In September 2022 the company said attackers stole personal and financial data on 50,150 customers.
My read: domain authentication tells you the envelope is real. It never tells you the request inside it is. Any bank that responds to law-enforcement requests by email alone, without a call-back to a number on the agency's public site and a second human approving the release, is going to keep making this exact mistake.



