Home · Technology · Sep 12 archive
Revolut Confirms Customer Data Breach Through Fake Government Requests
Confirmed
In Short: Revolut has confirmed a data breach after complying with a fraudulent government request, affecting a 'limited number' of its customers.
Revolut immediately blocked the address and alerted relevant agencies upon detection of the breach," a company spokesman told BNO News. "The incident highlights the sophistication of the scam, which utilized a legitimate government agency domain to submit fraudulent requests for customer information.
According to reports, the information shared with the malicious actor included KYC data such as full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers, as well as copies of ID documents and selfies. Revolut stated that fraudsters tricked the platform into handing over this data, including information that its own notices say covered passports and verification selfies.
Revolut's systems and customer funds remained unaffected, but the incident underscores the risks of relying on email verification alone. The company is reaching out to affected customers to provide additional support, though it declined to specify the number of people impacted.
What's confirmed
- Revolut immediately blocked the address and alerted relevant agencies upon detection of the breach," a company spokesman told BNO News. "The incident highlights the sophistication of the scam, which utilized a legitimate government agency domain to submit fraudulent requests for customer information.
- According to reports, the information shared with the malicious actor included KYC data such as full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers, as well as copies of ID documents and selfies. Revolut stated that fraudsters tricked the platform into handing over this data, including information that its own notices say covered passports and verification selfies.
- Revolut's systems and customer funds remained unaffected, but the incident underscores the risks of relying on email verification alone. The company is reaching out to affected customers to provide additional support, though it declined to specify the number of people impacted.
What's still developing
- “The infuriating part is that it happens right after Revolut sent me a notification to provide a LOT of data or ‘we will close your account in 20 days’,” Zeller wrote on X, formerly known as Twitter.
- Financial institutions are legally required to comply with official requests from law enforcement or government agencies, which are typically communicated through verified email addresses.
- Revolut has more than 70 million customers in over 40 countries and is valued at $75 billion, according to figures released in May.
- A Revolut spokesperson told BeInCrypto the bank blocked the sender as soon as it spotted the problem.
- Passcodes, login details, and biometric data were never exposed, the bank told BeInCrypto.
- Revolut will not say which agency’s domain was used, citing the live police investigation.
- The request came from a real government agency email domain and carried valid credentials.
- Revolut believed it was genuine and released the data.
