Skip to main content
Emerging ThreatsData Breaches

Revolut Breach Exposes Sensitive Data of Customers Worldwide

Modern office setting with laptop and papers on a desk, blurred cityscape visible through large window.

"Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency's email domain," the company told affected customers.

Revolut's disclosure and scale of the platform

Fintech firm Revolut disclosed that it shared customer data with a threat actor after the actor used an email that appeared to come from a government agency. Revolut — which operates in more than 160 countries and regions and provides banking, money-management, and investment services to more than 80 million customers worldwide, including 800,000 business customers — notified affected users by email, according to the company.

What was sent to the threat actor

In its notice to customers, Revolut said the data sent to the attacker included a wide range of personally identifiable information and account materials. The company listed identity details (full name, date of birth, occupation); contact details (postal address, email address, and telephone number); copies of identity documents (passport and/or driver's license); and facial verification images (selfies provided for Know Your Client verification when opening an account).

Revolut also said the exposed information included account statements (including IBAN numbers), withdrawal records, and full transaction history — the company explicitly noted this included Bitcoin transactions.

How the attacker obtained the data: impersonation via an agency domain

Revolut told customers the attacker requested PII via email "using a government agency's domain." According to the company, the request "appeared to come from a legitimate government agency" and "came from an unauthorised email account sent directly using the official government agency's email domain." Revolut said the communication carried "valid domain authentication credentials" and was fulfilled under the belief it was an authentic government agency request.

Scope, response, and prior incident

Revolut told Reuters the breach affects a "very limited" number of customers but declined to provide an exact figure. Upon detection, the company said it immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators. Revolut also stated that its systems and customer funds were unaffected.

Outside commentary cited in reporting flagged the likely focus of the intrusion. Crypto fraud investigator ZachXBT told reporters that while the breach likely affects a limited number of Revolut customers, "it seems to have been targeted at high net worth users." A Revolut spokesperson was not immediately available for comment when BleepingComputer reached out for further details.

Revolut previously disclosed a separate breach in September 2022, when attackers stole personal, contact, and financial information from 50,150 customers — a detail the company has now acknowledged in its public disclosure of the current incident.

What this means for affected customers, regulators, and business customers

  • Affected customers: Revolut has informed impacted individuals by email and described the specific categories of data that were shared. The company explicitly listed identity documents and transaction histories among the exposed items.
  • Regulators and enforcement bodies: Revolut said it alerted the relevant government agency and enforcement, data protection, and financial regulators after blocking the address used in the request — steps the company reported taking immediately upon detection.
  • Business customers and the broader client base: Revolut's global footprint — serving more than 80 million customers across 160+ countries, including 800,000 business customers — frames the potential reputational and oversight questions the disclosure raises, even as the company describes the number affected as "very limited."

Revolut's disclosure combines a detailed inventory of exposed records with a claim that its systems and customer funds were not compromised, while stopping short of publishing the exact number of customers affected. The company says it has taken immediate procedural steps — blocking the offending address and notifying government and regulatory bodies — and outside investigators have suggested the incident targeted wealthier account holders. The central unresolved fact remains the exact scope of customers whose sensitive identity and financial records were handed over after an apparently authenticated request.

Source: BleepingComputer — Revolut discloses data breach exposing financial info, passports