Tech & AI News
The Next Web

Revolut handed customer passports to scammers using a real government email domain

Revolut accidentally released customers’ dates of birth, addresses, emails, phone numbers, passports, driving licences, verification selfies, account statements and transaction histories. A fraudster used a legitimate government-agency email domain to request the data. Revolut confirmed its systems and funds were unaffected, blocked the address, notified the agency and regulators, and informed affected customers within 72 hours. The breach, reported by a crypto investigator, targeted high-net-worth individuals but involved no malware or credential theft.