Knowledge Center
Blog
Revolut Breach Shows Why Document ID Verification Fails

Revolut confirmed a data breach this week that did not involve any hacking at all. An attacker sent requests for customer information using an email address that looked like it belonged to a real government agency, and Revolut handed the data over because the request looked legitimate. No firewall was broken and no password was cracked. Just a convincing email taken at its word.
The customer data exposed in the Revolut breach included birth dates, home addresses, phone numbers, and copies of passports and driver's licenses. In some cases, the exposed data also included selfies that customers had submitted for identity verification and their full account histories.
Revolut has said that its systems and customer funds were not affected, and while that appears to be true, it is also beside the point. The thing that failed was the process Revolut used to decide who to trust.
Why document based identity checks keep failing
This is the part that should concern every fintech reading this story, not just Revolut. The way most companies verify identity today relies on things that can be faked, including scanned documents, selfies, and emails that appear to come from the right domain.
None of these things actually prove anything on their own. They are claims that happen to look convincing. A passport scan proves that someone has access to a passport scan. It does not prove that the person sending it is the person named on the passport, and it certainly does not prove that the person emailing from what looks like a government domain is actually from that agency.
This is also why so many recent breaches trace back to identity verification vendors and document based checks. When proof of identity is a photo of a document, the security of the whole system depends on how convincing a forged document can be, and forged documents have become very convincing.
What actually proves someone is who they say they are
At SLC, this is the exact problem we spend our time solving– proving that a real customer is who they claim to be, using something that cannot be copied, photographed, or sent from a fake email domain.
SLC does this by rooting identity in the SIM card that is already inside a customer's phone. That SIM contains a secure element, which is a small piece of hardware built specifically for cryptographic proof. The secure element can confirm device ownership in a way that a document scan never can, because it does not depend on anyone trusting a claim. It depends on the hardware answering a question it cannot lie about.
A document can be forged, and an email domain can be spoofed. A piece of secure hardware that is physically tied to a real device cannot be talked into pretending to be something it is not.
The lesson underneath the Revolut headline
Whenever a story like the Revolut breach happens, the usual response is to say that companies need to react faster and catch the fraud sooner. That response misses the actual problem, because the issue was never reaction speed. The foundation itself, which relies on documents and appearances to prove identity, was never solid to begin with.
Fixing that problem means building identity verification on something that cannot be faked in the first place. That is the idea behind hardware rooted identity, and it is why incidents like the Revolut breach will keep happening to companies that have not made that shift yet.


