IDV Article

Data breach: The impersonation scam hiding in a trusted channel

When a criminal ends up holding a complete onboarding package (the ID scan, the personal details, and the original verification selfie), what happens to identity verification everywhere else that person has an account, or might open one?

In an impersonation scam fueled by a data breach, criminals exploited a trusted channel to access sensitive identity records.

In September 2026, Revolut confirmed that customer data, including passports, driver’s licenses, and the verification selfies people took when they opened their accounts, had ended up in criminals’ hands. The company wasn’t hacked in the traditional sense. Instead, according to reporting from TechCrunch and the Financial Times, attackers appear to have compromised an official Italian government email account on the PEC (Posta Elettronica Certificata) system, Italy’s certified-mail channel for legal correspondence, and used it to submit what looked like a legitimate law enforcement request. Revolut’s compliance team, working through a channel designed to prove authenticity, handed over records on hundreds of customers, reportedly including many high-net-worth crypto holders identified through blockchain analysis.

It’s a breach with no malware and no broken lock, but not one without a vulnerability. The vulnerability was a process, not a piece of software: an unrecognized gap in how a trusted channel gets checked before sensitive data moves through it.

For an industry built on verifying identity, this incident raises a core question: when a criminal holds a complete onboarding package (ID scan, personal details, and verification selfie), what happens to that person’s security across other accounts?

We put that question, and others it raises, to Anu Liinev, Fraud Optimisation Manager at Veriff.

A complete identity package is worth more than the sum of its parts

“When a criminal holds a full onboarding package – a genuine document scan, personal details, and the original selfie – it effectively destroys the value of static biometric and document verification for that individual,” Liinev says. Traditional verification leaned heavily on matching a face to a document. With both pieces already in hand, a fraudster can try to replay those exact credentials at another platform, in another country, days, months, or years later.

While these represent some of the most common threat vectors Veriff sees, they are by no means an exhaustive list: fraudsters are creative and constantly find new ways to make a profit.

  • Account takeover and targeted social engineering: Armed with a victim’s full name, date of birth, address, phone number, and document copies, fraudsters impersonate a bank’s fraud department or a government official. They use the stolen details to sound credible, then coerce the victim into approving a 2FA push or moving funds to a “safe account.”
  • Synthetic identity creation: Genuine elements, like a real passport number or a real name, get combined with fabricated or stolen utility bills to open new accounts at banks, fintechs, and crypto exchanges, often as mule accounts for laundering money.
  • Loan and credit application fraud: Stolen government IDs get submitted to buy-now-pay-later providers and fast-credit lenders whose checks still rely mainly on static document verification.

Crucially, these paths are just snapshots of a rapidly changing landscape. Fraudsters are highly adaptive, constantly experimenting with new attack vectors and monetization strategies to turn stolen data into profit. Protecting against them requires assuming that attack methods will continuously evolve beyond the vectors known today.

A complete identity package is worth more than the sum of its parts and the shelf life of this data is far longer than most people assume.
“Physical documents eventually expire, creating a natural five-to-ten-year window for direct replay attacks using unaltered, authentic ID scans,” Liinev explains. “Synthetic identity fraud is different: it relies on data that never expires. Fraudsters feed made-up PII into editable digital templates and circulate modified variations for decades, until the issuing authority completely retires the underlying document design. This is one of the many reasons why maintaining a comprehensive, global document specimen database is a vital layer of defense.”

When isolated assets like a selfie or ID scan are combined with breached PII, such as SSNs, passwords, and phone numbers, they form an aggregated “identity dossier.” This complete profile gives bad actors the context required to satisfy multi-point verification checks, bypass static rule engines, and manipulate automated onboarding flows across banking, fintech, and crypto platforms.

quote

Synthetic identity fraud is different: it relies on data that never expires.

Anu Liinev Fraud Optimisation Manager Veriff

The stolen selfie doesn’t have to end verification for its owner

If the incident impacted your data, does that mean selfie-based verification is now off the table for you? “No, but we have to be clear that a leaked KYC file is a much higher-stakes threat than a casual social media photo,” Liinev says. A breached onboarding package is already formatted and calibrated for verification workflows, which makes it more dangerous than an ordinary photo pulled from a public profile.

This is precisely why modern identity verification doesn’t stop at matching a face to a document. Liinev points to two layers that specifically counter this scenario:

  • Presentation attack detection, which catches a fraudster physically holding up a leaked selfie, whether printed on paper, displayed on a screen, or built into a 3D mask.
  • Digital injection detection, which protects the capture stream itself, since sophisticated fraudsters with stolen KYC files increasingly skip the camera altogether and inject a pre-recorded, deepfaked, or synthetic video feed straight into the verification flow.

According to Liinev, Veriff has seen this pairing of stolen genuine documents with manipulated selfies grow into one of the fastest-moving attack vectors in the industry. Criminals buy leaked ID scans on the dark web, then combine them with face-swapped or AI-generated video designed to defeat liveness checks. Layering real-time anti-spoofing, injection detection, and device intelligence (confirming the session actually comes from a genuine smartphone camera rather than an emulator or virtual machine) makes it possible to verify that a real person is physically present at that exact moment, even when their static credentials have already leaked.

Add to that network and velocity signals (datacenter proxies, VPNs, geo-spoofing, rapid account attempts from one network) and behavioral analysis of how someone interacts with the camera during capture, and you get a picture built from many independent signals rather than one static match. A stolen selfie alone cannot bypass advanced verification systems that demand real-time proof of presence, but it continues to exploit platforms that still rely on static, image-to-image matching.

For a closer look at how deepfakes and injection attacks actually work, and how detection systems catch them, listen to episode one of Veriff Voices’ Deepfakes Series, where Veriff’s fraud and product teams break down the fastest-growing threats in identity fraud today.

The blind spot wasn’t the customer, it was the request

This case also points to a gap that sits outside the onboarding flow entirely: how a company verifies the people asking for customer data, not just the customers themselves.

“Financial institutions build highly secure biometric pipelines for customer onboarding, yet legal and law enforcement data requests often still pass through manual, email-based workflows,” Liinev notes. “Verification frequently relies on basic domain validation rather than confirming the individual officer or agent making the request.” That asymmetry, a hardened front door and a much softer back office, is exactly what attackers exploited, targeting compliance teams working against deadlines while completely bypassing customer-facing defenses.

The detail that the fraudulent requests in the data exposure came through Italy’s PEC system is worth sitting with. PEC is designed to prove that a message was sent and delivered through an official, legally recognized channel. “The fundamental lesson is that transport-layer or delivery certification is not the same as identity and authority verification,” Liinev says. “Credential theft, session hijacking, or a compromised email account mean an authenticated channel can easily carry a fraudulent payload.” As she puts it, arriving in a marked police car doesn’t earn someone access to a bank vault, and a certified email address shouldn’t earn someone a customer’s KYC file, either. Requests like these need out-of-band verification, cryptographic signature checks, or multi-party sign-off before sensitive data goes out the door.

quote

The fundamental lesson is that transport-layer or delivery certification is not the same as identity and authority verification.

Anu Liinev Fraud Optimisation Manager Veriff

Closing the gap means treating every handoff as a risk surface

None of this works as a patchwork of individual strong controls. “Fraudsters don’t only attack the components; they also attack the integration points,” Liinev says. A company might have excellent onboarding, a strong fraud engine, and a capable compliance team, and still be exposed if the handoffs between them (an API call, a vendor transfer, a manual review queue) go unmonitored. Closing that gap means applying the same zero-trust scrutiny to account recovery, high-value transactions, and third-party data requests that already protects the front door, and giving vendors and internal teams a clear, shared map of exactly who is responsible for which risk.

“Protecting consumer PII requires continuous, rigorous security from anyone handling sensitive data, but we must also acknowledge the broader threat landscape,” Liinev says. “Because high-profile breaches across the digital ecosystem continuously expose sensitive records, checks that rely solely on a photo of an ID paired with a selfie are simply no longer enough to guarantee safety online. Protecting people now means reading real-time context – such as live 3D depth, micro-expressions, device telemetry, network behavior, and digital injection signals – to confirm with high confidence that a real, trusted human is present at that exact second, regardless of what data may exist on the dark web.

What to do if you think your data was exposed

Breaches like this one don’t stay contained to the company that was hit. They spill outward fast, powering two parallel threats: mass phishing campaigns aimed at anyone they can reach, and hyper-targeted scams tailored directly to specific individuals using their stolen data.

Liinev has seen the mass approach firsthand: a family member with no account at the affected company received a scam message within a day of the news breaking. “Scammers are casting a wide, random net,” she says. But when criminals hold a complete onboarding package – your ID, personal details, and verification photo – they can just as easily drop the net and launch a surgical attack, using those exact details to build trust and manipulate a single person.

A few things to watch for:

  • Uncanny personal details. Tailored attacks may reference your real name, partial ID numbers, or specific account details to make a fake message feel completely genuine.
  • Urgency and emotion. Phishing relies on panic to make you act before you think.
  • Unsolicited links. Never click a link in an unexpected text or email claiming your account is locked, compromised, or requires urgent verification.

The golden rule, according to Liinev: if a message triggers a strong emotional reaction or demands immediate action, put your phone down, take a breath, and pause. Verify directly through official channels: never through the link or phone number provided in the message itself.

Stay vigilant, and pass this reminder along to family members too, especially those who assume they’re safe simply because they’ve never used the service in question.

That’s the piece individuals can actually control. The rest sits with the organizations holding the data in the first place. People can’t stop a company’s backend from being breached, or a compliance inbox from being fooled by a convincing email. “Phishing isn’t just an end-user threat; it’s an operational risk that targets human compliance workflows directly,” Liinev says. “Making an ecosystem resilient means pairing robust, automated verification technology with a culture of healthy skepticism across both consumers and internal compliance teams.” The Revolut incident is really a reminder that this kind of resilience has to run in both directions at once.

Take the next step

  1. Stay ahead of fraud trends. Subscribe to our newsletter for the latest research, data, and industry insights.
  2. See Veriff in action. Try the Identity Verification live demo and experience exactly what your users see.
  3. Talk to our team. Book a personalized demo and get answers to your specific questions.

Subscribe for insights

CTA form illustration

Start building with Veriff for free

Your journey toward faster, more accurate identity verification starts here.