Revolut Leak Shows the Cost of Constant ID Collection

Revolut’s mistake is the news, but the bigger problem is the growing number of companies being encouraged or required to keep copies of our most sensitive identity documents.

Photo: Revolut

If you’re tired of censorship and surveillance, subscribe to Reclaim The Net.

Online bank Revolut has revealed that it gave out sensitive personal and financial information of an undisclosed number of its customers in response to a fake government request.

The information that was handed over to an “unauthorized third party” reportedly includes names, dates of birth, occupations, addresses, phone numbers, account numbers, transaction histories (including Bitcoin), and even copies of government-issued IDs and onboarding verification selfies.

Revolut claims that derived biometric face data was not.

The company said that the data was handed over in response to an email that came from a real government agency’s domain, but was not actually sent or authorized by that agency.

The email passed several authentication checks (SPF, DKIM, and DMARC) that are designed to establish the authenticity of a message’s origin and integrity, but do not verify the legitimacy of the legal request itself.

Revolut said that it complied with the request “under the reasonable belief that it was an authentic government agency request” – and only later found out that it was not.

Revolut said it later realized its mistake, blocked the email address, and reported the incident to the relevant authorities.

Revolut said that only a “limited” number of its customers were affected by the data leak, and that the company’s systems were not hacked, nor was any money stolen.

The story broke on September 11 when Revolut customers started receiving an email notice about a data leak, and the news was picked up by media outlets the following day.

Revolut notice explaining customer identity and financial data was shared after an unauthorized government email request.

The reason this is a recurring problem is that companies are keeping highly sensitive information about their customers’ identities, and sometimes even financial transactions, for a long time, and this data is then available to be disclosed to third parties – either in response to valid legal requests, or, as in the case of Revolut, fake ones.

One reason for this is know your customer (KYC) and anti-money laundering (AML) rules. Revolut’s current UK customer privacy notice spells it out: the company generally keeps personal data of UK customers for no more than seven years after the relationship ends, and sometimes longer – for legal reasons.

This means that even if you close your account, your identity documents don’t disappear.

And while the incident with Revolut happened in the financial sector, it’s by no means the only one that requires customers to hand over sensitive identity information. Discord, a popular chat service, said in an October 9, 2025 security update that government ID photos of approximately 70,000 users may have been exposed after a third-party customer service provider got hacked.

This was not a financial service, nor the same type of attack. But the result was similar – because the underlying business process was the same: requiring and storing sensitive identity documents. In the case of Discord, these were used to review age-related appeals.

It’s hard to do anything about a copy of your old passport, or a photo of your face, or a record of your past transactions. These can be used to identify and profile you, and can be used to carry out targeted fraud. And this can happen even if the initial disclosure didn’t result in financial loss.

The more companies are forced to collect and store such information, and the more of it they have, the more opportunities there are for this data to be leaked, either by the company itself or a third party it works with. That's what makes governments' push for more ID checks just to access ordinary parts of life so reckless.