Home · Technology · Sep 12 archive

Revolut Confirms Customer Data Breach Through Fake Government Requests

Confirmed

Technology Desk

In Short: Revolut has confirmed a data breach after complying with a fraudulent government request, affecting a 'limited number' of its customers.

Revolut immediately blocked the address and alerted relevant agencies upon detection of the breach," a company spokesman told BNO News. "The incident highlights the sophistication of the scam, which utilized a legitimate government agency domain to submit fraudulent requests for customer information.

According to reports, the information shared with the malicious actor included KYC data such as full names, dates of birth, occupations, postal addresses, email addresses, and phone numbers, as well as copies of ID documents and selfies. Revolut stated that fraudsters tricked the platform into handing over this data, including information that its own notices say covered passports and verification selfies.

Revolut's systems and customer funds remained unaffected, but the incident underscores the risks of relying on email verification alone. The company is reaching out to affected customers to provide additional support, though it declined to specify the number of people impacted.

What's confirmed

What's still developing

Sources