Introduction

Revolut has confirmed a data breach involving sensitive customer information shared with unauthorized parties through fraudulent government requests. The incident raises concerns about security practices in digital banking.

What Happened

According to customer notifications, fraudulent requests sent from a legitimate government agency email domain led to disclosure of identity documents, contact details, and personal data. The compromised information may include birth dates, passport and driver's license copies, verification selfies, account statements, and transaction histories. Revolut stated it identified a sophisticated impersonation scam, blocked the originating email address, and alerted relevant authorities. The company emphasized that its systems and customer funds remain unaffected.

Why This Matters

With over 80 million customers across more than 30 countries, the breach highlights risks fintech platforms face from targeted impersonation attacks. The incident underscores how easily verified-looking government communications can be exploited to access sensitive user data. Experts warn that such breaches increase identity theft risks and emphasize the need for stronger authentication protocols across neobanks operating internationally.

Key Takeaways

  • Revolut confirmed a targeted impersonation scam using official-looking government emails to request customer data.
  • Exposed information includes identity documents, contact details, and potentially verification media and transaction records.
  • The company notified affected users directly and reported the incident to authorities.
  • No disruption to core banking systems or customer funds was reported.
  • The breach occurs as Revolut expands globally and pursues a potential public listing valuing the company at up to $200 billion.

Conclusion

Revolut scales its operations and eyes a major public market debut, and this breach serves as a critical reminder of the importance of rigorous security safeguards in fintech. Affected users are encouraged to monitor their accounts, enable additional verification where available, and stay alert for phishing attempts following the notification.