Revolut confirms customer data breach through fake government requests

Revolut said it disclosed sensitive customer information after an unauthorized party submitted fraudulent information requests using a legitimate government agency email domain. The company notified affected users, blocked the address, and reported the incident to the relevant government agency, law enforcement and financial regulators while saying its systems and customer funds were not affected.

By AI NewsroomPublished 25 minutes agoUpdated 25 minutes ago0 views
Revolut confirms customer data breach through fake government requests

Why It Matters

The breach involves personally identifying documents and account records for a subset of Revolut customers at a time when the firm is rapidly expanding globally and pursuing regulatory approvals and a potential public listing; given Revolut’s more than 80 million customers and recent moves into new markets, such incidents carry broader trust and regulatory implications.

Key Facts

  • Company: Revolut
  • Incident: Customer data disclosed to an unauthorized third party after fraudulent requests using a legitimate government agency email domain
  • Types of data exposed: Birth dates; postal and email addresses; phone numbers; copies of identity documents including passports and driver’s licenses; possibly verification selfies, account statements, and transaction histories
  • Scope: Described as a "limited" number of customers; exact number not disclosed
  • Action taken by Revolut: Notified affected customers, blocked the email address, alerted the relevant government agency, law enforcement, and regulators; said systems and customer funds unaffected

London-based fintech Revolut has confirmed that an unauthorized external party obtained customer information after submitting fraudulent requests from an email address using a legitimate government agency domain. The company told affected users by email and has taken steps to block the address used in the scam. According to the notification reviewed by TechCrunch, the exposed records included identity and contact details such as dates of birth, postal and email addresses, and phone numbers, as well as copies of identity documents including passports and driver’s licenses. Revolut said the data set may also have contained verification selfies, account statements, and transaction histories. A Revolut spokesperson described the incident as a sophisticated impersonation scam and said a limited number of customers were impacted, but the firm did not provide a precise count, identify the government agency whose domain was spoofed, or say whether the compromise was limited to a particular market. Security researcher ZachXBT posted about Revolut’s message and reported the incident appeared to target high-net-worth users. Revolut said it has alerted the relevant government agency, law enforcement, and financial regulators and emphasized that its systems and customer funds remain unaffected. The company operates globally with more than 80 million customers and banking operations in over 30 countries, and has recently expanded into markets including India, Mexico, France and the UAE while pursuing further regulatory approvals and potential growth initiatives.

Keep Reading