Revolut has disclosed a data breach after it shared customer data with a threat actor posing as a government agency, the fintech company said. The attacker submitted a request for personally identifiable information by email using a government agency's domain. Because the message carried valid domain authentication credentials, Revolut said it fulfilled the request in the reasonable belief that it came from an authentic government agency.
In notifications sent to affected customers, Revolut said the exposed data includes identity details such as full name, date of birth, and occupation. Contact details including postal address, email address, and telephone number were also shared. The data also included document and verification material, such as copies of passports or driver's licenses and facial verification selfies that customers provided during Know Your Client checks when opening an account.
Account statements containing IBAN numbers, withdrawal records, and full transaction history, including Bitcoin transactions, were also part of the data sent to the threat actor. Revolut told BleepingComputer that the breach affects a limited number of customers but declined to provide an exact figure. The company said its systems and customer funds were unaffected by the incident.
Revolut said it blocked the address immediately upon detecting the request and alerted the relevant government agency along with enforcement agencies, data protection authorities, and financial regulators. The company operates in more than 160 countries and regions and serves over 80 million customers worldwide, including 800,000 business customers. Revolut offers banking, money management, and investment services.
Crypto fraud investigator ZachXBT said over the weekend that while the breach likely affects a limited number of Revolut customers, it appears to have been targeted at high net worth users. The observation points to a possible focus on wealthier account holders rather than a broad sweep of the customer base. Revolut has not confirmed or commented on that characterization.
The disclosure follows an earlier Revolut breach four years ago, when attackers stole the personal, contact, and financial information of 50,150 customers in September 2022. The company has since faced scrutiny over how it handles customer data. The new incident adds to a growing list of cyberattacks targeting financial technology firms that hold sensitive identity and financial records.
More cybersecurity news from TechManNews.







