57 mins ago
Revolut Confirms Customer Data Breach After Fraudulent Government Requests
Revolut said some customer information was given to an unauthorised person.
The incident started when fake requests came from a real government agency domain.
The requests appeared legitimate because of where they were sent from.
The information may have included contact details, birth dates, and copies of identity documents.
Revolut said it blocked the address after discovering the problem.
It also notified government authorities, police, regulators, and data protection officials.
The company said its computer systems and customers’ money were not affected.
Security researcher ZachXBT said the incident appeared to focus on wealthy customers, but Revolut has not said how many people were affected.
Revolut said fraudulent requests from a legitimate government agency domain led to unauthorized disclosure of sensitive customer data.
Potentially exposed information included birth dates, postal and email addresses, phone numbers, passports, and driver’s licences.
The company said its systems and customer funds were unaffected and did not disclose how many people were impacted.
Revolut said it blocked the address and alerted the agency, law enforcement, data protection authorities, and financial regulators.
Security researcher ZachXBT said the incident appeared to target high-net-worth users as Revolut prepares for a potential IPO.
- Who
- Revolut customers were affected, while Revolut and an unauthorised third party were involved.
- What
- Sensitive customer information was disclosed after Revolut received fraudulent requests from a legitimate government agency domain.
- Where
- The incident involved Revolut, a London-based fintech operating across more than 30 countries; the specific location of the unauthorised third party was not stated.
- When
- The articles do not specify when the disclosure occurred; Revolut said it acted immediately after detecting it.
- Why
- Fraudulent requests were sent from a legitimate government agency domain, making them appear genuine.
Revolut’s Account
Security Concerns
Impact on customers
Revolut’s Account
Revolut said its systems and customer funds remained unaffected and did not announce the number of affected individuals.
Security Concerns
ZachXBT said the incident appeared to target high-net-worth users, highlighting concerns about the sensitivity and possible targeting of the exposed data.
Nature of the incident
Revolut’s Account
Revolut described the disclosure as resulting from fraudulent requests sent from a legitimate government agency domain and said it responded by blocking the address and alerting authorities.
Security Concerns
The incident indicates that attackers were able to use a trusted government-domain source to make requests appear legitimate, though the articles do not provide further details about how this happened.
Key facts
- Company
- Revolut, a London-based fintech and bank
- Customers
- More than 80 million globally
- Exposed data
- Identity and contact details, including birth dates, addresses, phone numbers, passports, and driver’s licences
- Financial impact
- Revolut said its systems and customer funds were unaffected
- Affected people
- The company did not disclose the exact number of individuals affected
- Response
- Revolut blocked the address and notified authorities, law enforcement, regulators, and data protection agencies
- Business context
- The breach comes as Revolut prepares for a potential IPO that could value it at up to $200 billion
Quotes
Revolut spokesperson
A spokesperson for Revolut who provided comments to Reuters.
“Upon detection, we immediately blocked the address and alerted the relevant government agency, as well as law enforcement agencies, data protection authorities, and financial regulators.”
firstpost.com
“Revolut systems and customer funds are unaffected”
firstpost.com





