Fake data requests pried passports out of Revolut

Published

Revolut has acknowledged that it handed sensitive customer records to somebody who was not entitled to them, after staff acted on fraudulent information requests sent from an email address on a genuine government agency's domain. The records that went out included copies of passports and driver's licenses, the selfies customers take to verify their identity, and complete transaction histories.

Nobody broke into anything. The requests simply looked official enough to answer.

A domain is not an identity

Revolut, a London-based banking and payments platform that says it has more than 80 million customers globally, describes the episode as an external impersonation scam rather than an intrusion into its systems, and says customer funds were not affected. It has not named the government agency and has not disclosed the domain that was abused, so how the sender came to be sending from it is not publicly known, and this briefing will not speculate about it.

That gap is close to the whole story. Banks field genuine data requests from law enforcement, regulators and government agencies constantly, and the address a request arrives from does a great deal of the work of proving it is real. Once a request is genuinely coming from inside a legitimate government domain, the check that most staff actually perform has already passed.

What went out of the door

Taken together, Revolut's own notice to customers and Check Point Research's weekly bulletin describe a broad set of disclosed data: names, dates of birth, postal addresses, email addresses and phone numbers; copies of identity documents including passports and driver's licenses; verification selfies; IBANs; account statements, withdrawal records and full transaction histories. That is close to everything a bank holds on a customer, and unlike a password none of it can be rotated afterwards.

Revolut has said only that a "limited" or "very limited" number of customers were affected, without putting a figure on it, and says it contacted those customers directly with a list of exactly which of their data was disclosed. In its statement the company said that "upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators". The account above is drawn from that statement and from the Malwarebytes Labs write-up.

The next call will know your transaction history

For the customers involved, the realistic risk is not money leaving the account tonight. It is the second stage. Somebody holding a passport scan, a verification selfie and a list of recent transactions can build a phone call that is very hard to refuse, because they can recite details only the bank should know.

Revolut's advice, which is also the sensible general rule, is to treat any unexpected contact about the account as suspicious, whether it arrives by phone, email, WhatsApp or text, and especially if it asks you to "secure" an account, reverse a transfer or replace documents. Do not use a link or a phone number supplied in the message; open the app and use its own support channel. Exposed identity documents argue for watching credit reports and new account openings too, since a passport copy has a far longer useful life to a fraudster than a card number does.

Why this keeps working

This is the same failure that has been running against corporate IT teams all year, pointed at a bank's compliance desk instead of a help desk. Callers posing as employees have talked support teams into registering new authentication methods on cloud accounts and, in one case, tried to talk their way onto a domain controller. The target is never the system. It is the person whose job is to be helpful, and the one signal they use to decide whether a request is genuine. Our United Kingdom profile tracks the wider picture.

Every organization that answers official-looking requests for customer data carries this exposure, and most of them still verify the sender by looking at the domain it came from.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions