Revolut handed customer passports to scammers using a real government email domain

https://media.thenextweb.com/2026/08/Revolut-Logo.jpg

Revolut gave sensitive customer information to criminals who requested it from what appeared to be a government email address, and did so because the address was real.

The company has confirmed the breach and says its systems were never touched; the story was reported by TechCrunch on Friday.

A Revolut spokesperson told TechCrunch the company had “identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information”, and added that “Revolut systems and customer funds are unaffected”.

What went out is what matters. Dates of birth, postal addresses, email addresses and phone numbers, plus identity documents including passports and driving licences.

TechCrunch reports that verification selfies, account statements and transaction histories may also have been disclosed. That is close to everything a person would need to impersonate a Revolut customer somewhere else, and unlike a password...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more