Advertisement
X

Revolut Confirms Sensitive Customer Data Breach After Fake Government Requests

Revolut confirms limited customer data exposure after fraudulent government requests, while saying its systems and customer funds remain unaffected

Summary
  • Fake government email requests exposed sensitive customer details at Revolut.

  • Customer funds and core banking systems remained completely unaffected throughout.

  • Affected users face higher risks of targeted phishing and impersonation attempts.

Advertisement

Revolut, a digital banking and financial services company, has confirmed that sensitive customer information was disclosed to an unauthorised third party after fraudulent requests were sent using a legitimate government agency email domain.

The fintech company, which has more than 80 million customers globally, said a limited number of customers were affected and that it has contacted them directly. Revolut did not disclose the exact number of people impacted or identify the government agency whose email domain was used.

What Customer Data Was Exposed In The Revolut Incident?

The information involved may have included customers’ names, dates of birth, postal and email addresses and phone numbers. Copies of identity documents, including passports and driving licences, may also have been exposed.

Verification selfies, account statements and transaction histories may have been included as well, according to a notification emailed to affected customers and reviewed by TechCrunch.

Advertisement

Revolut described the incident as an external impersonation scam. The unauthorised party used a legitimate government agency domain to submit fraudulent requests for customer information.

The company said it blocked the email address after identifying the activity and alerted the relevant government agency, law enforcement agencies and regulators.

Did The Revolut Data Breach Affect Customer Accounts Or Funds?

Revolut said its systems and customer funds were not affected by the incident. This means the incident involved the unauthorised disclosure of customer information rather than a reported compromise of its systems or customer balances.

The company has not disclosed whether the incident was limited to a particular market. Crypto security researcher ZachXBT, who posted about Revolut’s notification to affected customers, said the incident appeared to have targeted high networth users.

London-based Revolut operates as a bank in more than 30 countries and has expanded into markets including India, Mexico, France and the UAE. Earlier this month, the US Office of the Comptroller of the Currency granted conditional approval for Revolut to establish a national bank in the US. The company expects the bank to launch in the first half of 2027.

Advertisement

What It Means For Indians

For Indians using Revolut, the exposure of identity documents, contact details and transaction information could increase the risk of targeted impersonation or phishing attempts using their personal details.

Revolut, which has expanded its presence in India, has said the incident affected a limited number of customers. The company has not disclosed how many customers were impacted or provided a market-wise breakdown of the affected users.

Show comments
Published At: