Revolut breach: your vendor's support desk is an auth gap
Revolut handed over passports, selfies and transaction histories after a fraudulent request from a real government email domain. What operators should check.
Revolut confirmed on September 12 that it disclosed customer identity documents to an unauthorized third party. No malware, no exploit, no stolen credentials. Someone sent a fraudulent data request from a legitimate government agency's email domain, and it passed. If you keep customer data with a vendor — and you do — this is the failure mode nobody puts in a security questionnaire.
What actually happened
Per TechCrunch, a Revolut spokesperson described "a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information." The domain was real. It passed authentication. The request was not.
What went out: birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver's licenses. Revolut says the disclosure may also have included verification selfies, account statements, and transaction histories. The Block reports that Bitcoin transaction history was among the exposed data.
Revolut says a "limited" number of customers were affected and that it contacted them directly. It has not published a number, has not named the agency, and states that systems and customer funds are unaffected. Onchain investigator ZachXBT surfaced the incident publicly before Revolut confirmed it, and suggested the targeting was aimed at high-net-worth individuals. We are reporting only what Revolut and established outlets have confirmed — treat the targeting claim as unverified.
Why it matters for your business
Every vendor holding your data runs a channel that exists specifically to hand that data to someone who asks convincingly. Law enforcement requests, emergency disclosure requests, account recovery, "the customer is locked out and their COO is escalating." That channel is a human reading an email, and email domain authentication proves the message left a given mail server — not that the person behind it has the authority they claim.
Three things worth doing this month:
Ask your vendors how they verify requests, in writing. Not "do you have a process" — ask what the callback verification is and who signs off. A vendor that cannot describe an out-of-band confirmation step does not have one.
Inventory what your vendors can be asked for. If a support agent at your payment processor, your CRM, or your KYC provider could be socially engineered tonight, what leaves the building? Most operators have never listed it. Identity documents are usually on that list, and they do not rotate.
Stop storing what you do not need. The cleanest defense against a vendor's disclosure channel is a vendor that never had the file. Verify, retain the result, drop the scan.
Key takeaways
- Revolut confirmed on September 12 that it disclosed customer data after a fraudulent request sent from a legitimate government agency email domain
- Exposed: birth dates, contact details, passport and driver's license copies; possibly verification selfies, statements, and transaction histories
- Revolut calls the affected group "limited," has not published a count, and has not named the agency
- Domain authentication proved the mail server, not the requester's authority — the control that failed was human verification
- Audit every vendor's data-disclosure channel and ask in writing how out-of-band verification works
- Identity documents do not rotate like passwords; the best control is not holding the scan at all
Not sure what your vendors could be talked into handing over? We map where customer data actually lives across your stack and cut the copies you do not need to keep. See how we handle data architecture, or tell us which vendors worry you.
Sources: TechCrunch, The Block.
- #data-breach
- #vendor-risk
- #social-engineering
- #kyc
- #fintech
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Oracle's $2.8B severance bill: capex outruns cash
Oracle's 10-Q shows $28.5B of quarterly capex against $23.1B operating cash, plus $700M more severance. What a strained vendor does to your contract.
Read itMeta rebuilds manager ranks AI was supposed to replace
Meta cut 8,000 roles to go flat for AI, then asked engineers in its Applied AI division to become managers again. The coordination cost lesson for small teams.
Read it