Revolut Confirms Data Breach Through Government Email Scam
Revolut has confirmed that sensitive customer information was disclosed to an unauthorized third party after the company received fraudulent data requests from an email address using a legitimate government agency domain. The incident involved a limited number of customers, although Revolut has not stated how many people were affected.
The exposed information may have included names, dates of birth, postal and email addresses, and telephone numbers. Copies of identity documents, such as passports and driver’s licenses, may also have been disclosed. Revolut said some affected records could have included verification selfies, account statements, and transaction histories.
The company said the incident resulted from a sophisticated impersonation scam. An unauthorized person used an email address associated with a genuine government domain to submit requests for customer information. Revolut blocked the address after identifying the fraud and notified the relevant government agency, law enforcement authorities, and regulators.
Revolut said its systems and customer funds were not affected. The company also confirmed that it contacted customers believed to have been involved. However, it has not disclosed the government agency concerned, the country or market affected, or the precise number of customers whose information may have been accessed.
The incident was reported publicly after crypto security researcher ZachXBT shared details of Revolut’s notification to affected customers. He suggested that the attack may have focused on high-net-worth individuals. The company operates in more than 30 countries and has over 80 million customers worldwide.
The disclosure comes while Revolut is reportedly considering a public listing that could value the company at up to approximately €170 billion, compared with its private valuation of about €64 billion in November. From a data protection perspective, the incident raises questions about identity verification, the handling of government requests, access controls, and the company’s obligations under the EU General Data Protection Regulation.
Under the GDPR, a personal data breach must be assessed promptly to determine whether it creates a risk to individuals’ rights and freedoms. Where the legal conditions are met, the controller must notify the relevant supervisory authority within 72 hours of becoming aware of the breach and inform affected individuals without undue delay when the risk is high. Customers who received a notification should remain alert for identity fraud, phishing messages, and suspicious account activity.