Revolut has disclosed a data breach in which sensitive information belonging to a limited number of customers was shared with an unauthorized third party. The incident happened after someone impersonated a government agency and sent information requests using an email domain belonging to a legitimate government organization. Because the messages passed valid domain authentication checks, Revolut believed the requests were genuine and provided the requested customer information. The company has not revealed exactly how many customers were affected or identified the government agency involved.
According to information sent to affected customers, the exposed data included several types of personal information. This included customers’ full names, dates of birth, occupations, postal addresses, email addresses and telephone numbers. Copies of identity documents, including passports and driving licences, were also included, along with facial verification images or selfies used during the customer verification process. The incident therefore involved both personal identification information and documents that customers had provided to verify their identities.
The exposed information was not limited to identity documents and contact details. Revolut’s customer notification also listed account statements, including IBAN numbers, withdrawal records and complete transaction histories. These transaction records could also include Bitcoin transactions made through Revolut. This makes the incident particularly sensitive because the information could reveal details about a customer’s financial activity, rather than simply exposing basic contact information. Revolut has described the number of affected customers as limited.
Revolut said the incident was caused by an external impersonation attack rather than someone breaking directly into its systems. Once the company discovered that the requests were fraudulent, it immediately blocked the email address involved and alerted the relevant government agency. Revolut also notified law-enforcement authorities, data-protection authorities and financial regulators about the incident. The company has stated that its systems and customer funds were not affected, meaning there is currently no indication that customer money was taken during the incident.
The incident has also raised concerns about how attackers can misuse trusted communication channels. In this case, the fraudulent requests appeared legitimate because they came through a real government domain and carried valid authentication credentials. That allowed the attacker to make the request look like an official government demand, showing that technical email authentication alone cannot always prove that the person making a request is authorized to receive sensitive information. Revolut has described the incident as a sophisticated external impersonation scam.
Revolut has contacted customers believed to be affected and has taken additional steps after discovering the breach. The company has not publicly confirmed the exact number of people involved, the specific government agency whose domain was used, or whether the incident affected customers in a particular country or market. A crypto fraud investigator has suggested that the breach may have been aimed at high-net-worth customers, but that assessment has not been confirmed by Revolut. The company’s investigation and response remain focused on understanding the incident and protecting affected customers.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news