Revolut just handed over customer passports, driving licences, bank statements, and verification selfies to criminals. And nobody had to hack anything to get it.
That’s the part that should actually worry you.
No breached servers. No cracked passwords. No malware. Someone sent an email, and the bank handed the data over willingly.
A Real Domain Isn’t a Real Request
Here’s how it worked: an attacker got into an unauthorised mailbox sitting on a legitimate government domain, and used it to submit data requests. The domain wasn’t spoofed or faked, it was genuine. And that’s exactly the problem.
A real email domain only proves where a message came from. It doesn’t prove who actually sent it. Once someone is inside that mailbox, every request they send carries the authority of the organisation behind it, even though the organisation has no idea it’s happening.
Revolut treated the request as legitimate, because by every normal signal, it looked legitimate. And what went out the door was comprehensive: full names, dates of birth, driving licences, the verification selfies used to open accounts, copies of transaction history, even bitcoin activity. All of it, straight out.
Why the Biometric Scan Doesn’t Save You
The selfie verification, the ID scan at sign-up, the biometric checks that fintechs are so proud of, they’re brilliant, until the underlying documents themselves are the thing that’s stolen.
If someone has your passport and your spending habits, they don’t need to break through your bank’s security. They need about 30 seconds on the phone with you, pretending to be your bank’s fraud team, quoting details back to you that only your bank should know. That’s it. That’s the whole attack. Every piece needed to run a convincing scam is now sitting with the people who took it.
This Is Bigger Than One Fintech
The uncomfortable truth is that this doesn’t just implicate Revolut. Every crypto exchange and every company that scans your ID at sign-up runs on the same underlying assumption: that a request coming from a real domain is a real request. That trust is the whole foundation of how these verification processes work, and it’s exactly the trust that just got turned into a weapon.
What To Actually Do About It
If you bank with anyone, the practical takeaway is simple: be suspicious of calls asking detailed questions about your account, even if the caller seems to know things about you. If something feels off, hang up and call back on a number you trust.
In the UK, dial 159, the short code that routes you straight through to your own bank’s genuine fraud line, no matter who you bank with, and one that scammers cannot spoof.
The Real Headline
Revolut didn’t get hacked. They got played, and that distinction matters more than it sounds like it should. A hack is a technical failure you can patch. A con is a process failure, and those are much harder to engineer your way out of. They’ve been conned, and if a company handling millions of customers’ identity documents can be talked out of the data this easily, it’s worth asking how many other “legitimate” requests are sailing through the same door.