Revolut confirms customer data breach after scam

Revolut confirms customer data breach after scam

Revolut has confirmed customer data was disclosed to unauthorised parties. Fraudulent requests sent through a legitimate government email domain exposed sensitive information, putting verification controls and social-engineering risk under scrutiny.


Revolut has confirmed that sensitive customer information was disclosed to an unauthorised third party after fraudsters used a legitimate government-agency email domain to submit false requests for data.

The fintech group said only a limited number of customers were affected and that neither its core systems nor customer funds were compromised.

The incident did not involve attackers breaking into Revolut’s banking infrastructure. Instead, the company was deceived into responding to requests that appeared to originate through an authentic official channel, shifting the security failure from network intrusion to identity verification and internal controls.

Information disclosed included customer contact and identity data. Notifications sent to affected users identified information including dates of birth, postal and email addresses, telephone numbers, and copies of identity documents such as passports and driving licences.

Depending on the customer, other records may have included verification photographs, account statements, and transaction information.

Revolut said the fraudulent address was blocked after the activity was identified and that the relevant government agency, law-enforcement bodies, data-protection authorities, and financial regulators had been notified.

A company spokesperson said: “Revolut systems and customer funds are unaffected.”

The business contacted affected users directly. It initially described the group as “very limited”, while subsequent reporting put the number at close to 700 customers.

The breach illustrates a security problem that conventional cyber defences cannot solve on their own. Banks and other organisations holding sensitive information routinely receive genuine requests from governments, courts, regulators, law-enforcement bodies, and other authorised organisations.

The control challenge is verifying the identity and authority of the person making the request even where the communication arrives through what appears to be a trusted domain.

An authentic email address can provide a strong signal of legitimacy without proving that the person using the account is authorised or that a specific request is genuine. Compromised official accounts, impersonation, and social engineering can therefore defeat processes designed mainly to identify suspicious external senders.

That places greater weight on secondary verification. A request for identity records or financial data may need confirmation through an independent contact route before information is released, particularly where large volumes of personal data are involved.

The incident also strengthens the case for limiting disclosure to the minimum information required. The decision to release customer information is itself a security-sensitive action, even when it takes place through a compliance or legal-response function rather than a technical system.

The consequences extend beyond the cost of investigation and customer notification. Digital banking depends heavily on customers trusting providers with identity documents, payment information, financial histories, and other sensitive records.

Revolut has become one of Europe’s largest fintech businesses and serves tens of millions of customers globally. That scale increases both the value of the information it holds and the scrutiny applied to its controls.

The company is also continuing to develop its international banking operations, making operational resilience and governance increasingly important alongside customer growth.

Regulators are likely to examine how the disclosure was authorised, what verification controls were applied, how quickly the activity was detected, and whether procedures for responding to government or law-enforcement requests require additional safeguards.

For affected customers, the absence of an account-system breach does not eliminate risk. Identity documents, contact details, transaction information, and other personal records can be used in subsequent impersonation attempts or highly targeted fraud.

The distinction between technical hacking and social engineering has become increasingly important as cyber controls improve. Attackers have greater incentive to target employees, suppliers, and trusted communication channels when direct intrusion becomes more difficult.

Financial institutions therefore have to secure both their technology and the business processes through which sensitive information can legitimately leave the organisation.

Revolut’s systems remaining intact limits the immediate operational impact. The breach nevertheless demonstrates that apparently authentic official communications can carry the same disclosure risk as overtly hostile ones if independent verification fails.



  • UK and US link fusion AI supercomputers

    UK and US link fusion AI supercomputers

    UK and US fusion laboratories are linking powerful AI supercomputers. The proposed federation will combine experimental data and computing capacity as both countries pursue faster fusion development and commercialisation.


  • FCA explores tokenised gold for UK markets

    FCA explores tokenised gold for UK markets

    The FCA is testing how tokenised gold could reshape markets. Its work examines trading, transfers, collateral, custody, and regulation as the UK develops a broader framework for tokenised wholesale finance.


  • The leadership opportunity behind Britain’s workplace suicide standard

    The leadership opportunity behind Britain’s workplace suicide standard

    Workplace suicide prevention is becoming an urgent board-level governance priority. MHFA England CEO Sarah McIntosh argues BS 30480 gives employers a framework to connect trained staff, escalation pathways, and executive accountability before workplace support breaks down.