By Sumedha Mukherjee
Revolut has confirmed that sensitive customer information was disclosed to an unauthorized third party after it received fraudulent requests from a legitimate government agency email domain.
Revolut said in a statement that the breach affected a “very limited” number of customers, who it has notified. It did not confirm the number of affected customers.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the firm said.
Revolut said it has since blocked the email address after discovering the scam.
The compromised data included customers’ birth date, postal and email addresses, and phone numbers. Additionally, it included selfies and copies of their identity documents, including passports and driver’s licenses.
Accounts claiming to be behind the attack have started posting what they claim to be sensitive customer data online.
They want Revolut to pay them. They have not yet pubicly posted an amount. The accounts claim that Revolut gave sensitive customer information to countries outside its jurisdiction, accusing the firm of negligence around privacy.
ZachXBT, a security expert who first reported details of the Revolut data breach, said the attackers may have targeted wealthy users.
In a statement, Revolut said: “Revolut systems and customer funds are unaffected.” The company did not disclose the exact number of individuals affected by the breach.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.
Revolut is planning for a potential public listing and aiming for a valuation of up to $200 billion.
It is one of the most successful European fintech companies, with no physical bank branches.










