Fintech company Revolut confirmed that it inadvertently disclosed sensitive customer information to an unauthorized third party. The breach occurred after the company received fraudulent data requests that originated from an email domain belonging to a legitimate government agency. This sophisticated impersonation scam bypassed Revolut's initial security checks, leading to the data release.
The compromised data includes customers' identity and contact details such as birth dates, postal and email addresses, phone numbers, and copies of identity documents like passports and driver's licenses. Revolut's notification to affected customers also indicated that verification selfies, account statements, and transaction histories might have been exposed. The company stated that a "limited" number of customers were impacted but did not provide an exact figure or specify if the incident was geographically limited.
Upon discovering the scam, Revolut blocked the fraudulent email address and alerted the relevant government agency, law enforcement, and regulators. The company emphasized that its systems and customer funds remain unaffected by this incident. Revolut has over 80 million customers globally and operates as a bank in more than 30 countries, with recent expansions and regulatory approvals, including conditional approval for a national bank in the U.S.
The incident was brought to public attention by crypto security researcher ZachXBT, who noted that the breach appeared to target high-net-worth users. This event occurs as Revolut reportedly considers a potential public listing, which could value the company significantly. Such security incidents can impact customer trust and regulatory scrutiny, particularly for financial institutions handling sensitive personal and financial data.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Revolut disclosed that an unauthorized third party obtained sensitive customer data by submitting fraudulent requests from a legitimate government agency email domain. The exposed information includes identity details, contact information, and potentially verification selfies, account statements, and transaction histories for a limited number of customers. This incident highlights vulnerabilities in data access protocols, even when dealing with seemingly legitimate government communications.