REVOLUT is notifying a limited number of users that personal and financial information was exposed after an unauthorised party impersonated a government agency. The London-based fintech, which says it serves more than 80 million users across 160 countries and regions, said the fraudulent requests were submitted from a legitimate government-agency email domain and carried valid technical domain credentials. They were therefore treated as genuine official enquiries.
According to emails sent to affected customers, the exposed information included names, addresses, telephone numbers, email addresses, dates of birth, occupations, copies of driving licences and passports, and verification selfies. Financial data was also involved, including IBANs, account statements, withdrawal records and complete transaction histories, including Bitcoin transactions. Revolut has not disclosed how many people were affected, but said only a subset of users was involved.
The company said it blocked the attacker’s email address after discovering the breach and notified the relevant government agency, law-enforcement bodies, data-protection authorities and financial regulators. Revolut said its systems and customer funds were not affected, and that it had contacted impacted individuals directly to provide support. The report does not confirm misuse of the exposed information or provide evidence of further unauthorised access.