REVOLUT has acknowledged disclosing sensitive customer information to an unauthorised party after accepting fraudulent requests sent from an email address on a legitimate government-agency domain, according to reports cited by Malwarebytes. The London-based financial platform, which says it has more than 80 million customers globally, described the incident as an external impersonation scam rather than an intrusion into its systems. It said customer funds were not affected, but did not identify the government agency or disclose the domain involved.
The attacker appears to have exploited trust in the genuine government address to obtain customer records through social engineering. Potentially exposed information included dates of birth, postal addresses, email addresses, telephone numbers, passport and driving-licence copies, verification selfies, account statements and transaction histories. Revolut has described the number of affected customers as “limited” or “very limited” and said it is contacting them directly with details of the data disclosed.
The company detected the activity, blocked the sending address and notified the relevant agency, law-enforcement bodies, data-protection authorities and financial regulators.
The likely risk is follow-up identity theft and fraud rather than immediate unauthorised transfers. Customers who receive a notification should check balances, cards, beneficiaries, transfers, statements and linked devices, and report suspicious activity through Revolut’s secure in-app chat. They should also treat unexpected calls, emails, WhatsApp messages or texts about securing an account, reversing a transfer or replacing documents with caution, avoiding links and contact details supplied in those messages.