Revolut handed over passports and selfies to someone pretending to be a government agency
Revolut was not hacked. That is what makes this one worth reading about.
On Monday the bank confirmed that somebody emailed it asking for customer records while posing as a government agency, and it sent them over. The request arrived from a genuine government domain and passed the checks that are supposed to prove an email is what it claims to be, so staff treated it as routine paperwork. What went out was not a list of email addresses. It was passport and driving licence scans, the selfies people take during account verification, dates of birth, home addresses, occupations, phone numbers, account statements with IBANs, withdrawal records and complete transaction histories including crypto.
Revolut says only "a limited number" of customers were caught, that its systems were never touched and that nobody's money moved. It blocked the address on detection and told the government agency, law enforcement, data protection and financial regulators. The people holding the data have been less restrained. They have posted samples in Telegram groups and demanded 10,000 Bitcoin, roughly 780 million dollars, threatening to release more every day until Revolut pays. Crypto investigator ZachXBT reckons the targeting leaned towards wealthier account holders.
Here is the part that matters for everyone else. A passport scan plus a matching selfie is the exact package needed to open accounts in your name or talk a support agent into a reset. And anyone who phones you now claiming to be Revolut can read out your last few transactions, which is precisely what makes a fake fraud-team call land. No bank will ever ring you and ask you to move money to a "safe account"; hang up and use the app's own chat. Tendvane's privacy and accounts check goes over the sign-in and recovery settings on your PC, which is the other half of the door these people try next.