<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/revolut-handed-customer-identity-documents-to-scammers-who-spoofed-a-government-email-domain-qeofxsljc" -->

---
title: Revolut handed customer identity documents to scammers...
description: Revolut confirmed that fraudsters impersonating a legitimate government agency&#x27;s email domain tricked the company into handing over sensitive customer data,...
canonical: https://daily.dev/posts/revolut-handed-customer-identity-documents-to-scammers-who-spoofed-a-government-email-domain-qeofxsljc
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Revolut handed customer identity documents to scammers who spoofed a government email domain | daily.dev
og:description: Revolut confirmed that fraudsters impersonating a legitimate government agency&#x27;s email domain tricked the company into handing over sensitive customer data,...
og:url: https://daily.dev/posts/revolut-handed-customer-identity-documents-to-scammers-who-spoofed-a-government-email-domain-qeofxsljc
og:image: https://api.daily.dev/og/posts/QeOfXsLJc.png
og:image:alt: Revolut handed customer identity documents to scammers who spoofed a government email domain
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Revolut handed customer identity documents to scammers who spoofed a government email domain

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Revolut confirmed that fraudsters impersonating a legitimate government agency's email domain tricked the company into handing over sensitive customer data, including passports, driving licences, addresses, dates of birth, phone numbers, and possibly verification selfies and account statements. Customer funds and systems were reportedly unaffected. Revolut blocked the email address, notified affected customers and regulators, and alerted the impersonated agency, but hasn't disclosed how many customers were affected, which markets were involved, or how the fraudulent requests bypassed internal verification. Crypto investigator ZachXBT surfaced the incident and suggested it may have targeted high-net-worth individuals, a claim that remains unverified. The breach comes as Revolut launches a private banking arm and pursues a reported IPO that could value the company at up to $200 billion.

## Content

Revolut has confirmed a data breach in which criminals tricked the company into handing over sensitive customer information by impersonating a legitimate government agency using a spoofed but domain-authenticated email address.

The exposed data includes identity documents such as passports and driving licences, addresses, dates of birth, phone numbers, IBANs, full transaction histories including Bitcoin transactions, and possibly verification selfies and account statements. Revolut says its systems and customer funds were not compromised, and that it has blocked the email address, notified affected customers, alerted the impersonated agency, and informed law enforcement and regulators.

The company has not disclosed how many customers were affected, which markets they are in, which government agency's domain was used, or exactly how the fraudulent requests passed internal verification. It has described the number of affected customers only as "very limited."

Crypto fraud investigator ZachXBT surfaced the incident and claimed the attackers specifically targeted high-net-worth individuals, though that claim has not been independently verified. It's worth noting that Revolut recently launched a private banking arm aimed at wealthy clients, which would make such targeting plausible if not confirmed.

This is not Revolut's first breach. In 2022, attackers accessed data belonging to more than 50,000 customers in a separate incident.

The timing is awkward for the company, which is pursuing a potential IPO at a reported valuation of up to $200 billion and has been expanding its global banking footprint. A breach involving KYC documents and financial records is exactly the kind of story that tends to follow a company into its roadshow.

The core problem here is that Revolut, like most financial institutions, has processes for responding to government information requests, and those processes apparently did not catch a spoofed request that used a real domain. That's a meaningful gap. Blocking the specific email address after the fact doesn't address how the request was validated in the first place.

## Questions this post answers

### What customer data did Revolut expose in the recent data breach involving a spoofed government email?

Fraudsters impersonating a government agency's email domain tricked Revolut into disclosing customer identity documents including passports and driving licences, along with home addresses, dates of birth, and phone numbers. Verification selfies and account statements may also have been exposed. Revolut says customer funds and systems were not affected, but has not disclosed how many customers or which markets were involved.

_Following fintech security incidents like this helps developers building identity verification systems avoid similar gaps, a habit daily.dev supports._

### How did scammers trick Revolut into handing over customer identity documents?

Scammers spoofed or compromised a legitimate government agency's email domain and submitted fraudulent information requests that Revolut's compliance process accepted based on the sender's email domain alone, without additional verification. This gap allowed sensitive identity documents and personal data to be disclosed to attackers rather than the actual agency.

_Developers designing verification workflows can compare real-world failures like this one via daily.dev before shipping their own compliance checks._

## Similar posts on daily.dev

- [Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider](https://daily.dev/posts/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-pr-je4d4ipgf) · TechCrunch · 1 upvotes · 0 comments

---

Tags: [#fintech](https://daily.dev/tags/fintech), [#phishing](https://daily.dev/tags/phishing), [#data-breach](https://daily.dev/tags/data-breach), [#identity-verification](https://daily.dev/tags/identity-verification)

[View this post on daily.dev](https://daily.dev/posts/revolut-handed-customer-identity-documents-to-scammers-who-spoofed-a-government-email-domain-qeofxsljc)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Revolut handed customer identity documents to scammers who spoofed a government email domain","url":"https://daily.dev/posts/revolut-handed-customer-identity-documents-to-scammers-who-spoofed-a-government-email-domain-qeofxsljc","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/revolut-handed-customer-identity-documents-to-scammers-who-spoofed-a-government-email-domain-qeofxsljc"},"datePublished":"2026-09-13T16:09:12.867Z","dateModified":"2026-09-14T12:27:32.258Z","description":"Revolut confirmed that fraudsters impersonating a legitimate government agency's email domain tricked the company into handing over sensitive customer data,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fa00966a97d68deef27da169aef41cc7?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fa00966a97d68deef27da169aef41cc7?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/revolut-handed-customer-identity-documents-to-scammers-who-spoofed-a-government-email-domain-qeofxsljc","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"fintech,phishing,data-breach,identity-verification","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Revolut handed customer identity documents to scammers who spoofed a government email domain"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/revolut-handed-customer-identity-documents-to-scammers-who-spoofed-a-government-email-domain-qeofxsljc#faq","mainEntity":[{"@type":"Question","name":"What customer data did Revolut expose in the recent data breach involving a spoofed government email?","acceptedAnswer":{"@type":"Answer","text":"Fraudsters impersonating a government agency's email domain tricked Revolut into disclosing customer identity documents including passports and driving licences, along with home addresses, dates of birth, and phone numbers. Verification selfies and account statements may also have been exposed. Revolut says customer funds and systems were not affected, but has not disclosed how many customers or which markets were involved. Following fintech security incidents like this helps developers building identity verification systems avoid similar gaps, a habit daily.dev supports."}},{"@type":"Question","name":"How did scammers trick Revolut into handing over customer identity documents?","acceptedAnswer":{"@type":"Answer","text":"Scammers spoofed or compromised a legitimate government agency's email domain and submitted fraudulent information requests that Revolut's compliance process accepted based on the sender's email domain alone, without additional verification. This gap allowed sensitive identity documents and personal data to be disclosed to attackers rather than the actual agency. Developers designing verification workflows can compare real-world failures like this one via daily.dev before shipping their own compliance checks."}}]}
```

