Revolut confirms customer data breach through fake government requests

Revolut has confirmed a data breach in which attackers, posing as government or law-enforcement agencies over email, obtained sensitive customer information, potentially including ID documents and “selfie” videos used for KYC. Commenters highlight how ad‑hoc, insecure channels for official data requests, weak authentication of authorities, and legal obligations to respond create systemic risks that even “modern” fintechs often handle poorly. The incident also renews criticism of mandatory ID data retention, automated identity verification, and Revolut’s broader security and compliance track record.

Law-enforcement requests & email security

  • Several commenters with LE-request experience say most requests arrive as emailed PDFs from “.gov-ish” addresses, often without secure channels.
  • Controls commonly used: verifying DKIM, checking letterhead, and calling back using independently sourced phone numbers; but time pressure and legal obligations often weaken rigor.
  • Some note many official domains lack proper SPF/DKIM/DMARC, making spoofing easy; others argue a DKIM-authenticated email would imply a government-side compromise.
  • A key criticism: Revolut allegedly treated “email from a real-looking government domain” as sufficient authorization, rather than verifying the requester, channel, and scope.
  • Suggested good practice: strict channel lists, mandatory callbacks, reference-number verification, and limiting emergency responses to minimal datasets.

KYC, selfies, and data retention

  • Debate over why selfie/video and ID scans are stored:
    • Some say regulation/AML requires retaining proof for years.
    • Others argue you only need to record that checks were done, not keep full scans; reply notes EU rules typically require retaining evidence but with eventual deletion.
  • Disagreement on prevalence of selfie KYC:
    • Some say “most banks now require selfies.”
    • Others report opening accounts without selfies or only doing in-branch ID checks (though those IDs are still scanned).
  • Concern that KYC providers, not just banks, store this data and may not invest in “cold storage”–style protections.

Revolut’s security culture and history

  • Multiple comments characterize Revolut as prioritizing growth and low costs over security and support quality.
  • Past issues mentioned: disabled AML detection, using job applicants as unpaid lead generators, failing to freeze accounts on request, and high fraud/chargeback statistics.
  • Support is described as heavily automated and hard to escalate to humans; breach notifications may be lost amid marketing emails.

User impact, rights, and trust

  • Some users report Revolut told them they were not affected; others question how this can be verified and note legal limits on disclosing LE access.
  • EU/UK data and banking laws are cited, but there is disagreement on what must be disclosed and when.
  • Several commenters conclude that once such identity data is leaked, especially linked to on-chain crypto activity, the risk is long-lived.

Broader takeaways

  • Government access to private data is framed as a de facto “backdoor” that attackers can also exploit.
  • Legacy banks are seen as clunky but often more battle-hardened on security; modern fintechs are viewed as more exposed to social engineering.