Revolut discloses customer data after fraudsters spoof government email
Scope of Compromised Customer Information
British fintech Revolut revealed this week that it mistakenly handed over sensitive customer information to fraudsters who sent fake requests using a legitimate government agency's email domain. The breach exposed personal details including birth dates, postal addresses, email addresses, and phone numbers of an undisclosed number of users.
Breaking news:
The company discovered the unauthorized disclosure after identifying that the fraudulent requests appeared to originate from a verified government email address, lending them credibility. Revolut immediately launched an investigation, notified affected customers, and reported the incident to the relevant government agency and law enforcement authorities.
How Did the Fraudsters Bypass Security?
The exposed data included core identity and contact details but did not involve financial account credentials or transaction history. Revolut emphasized that no customer funds were at risk and that the breach was limited to personally identifiable information used for account verification and communication purposes.
A company spokesperson stated that Revolut acted swiftly to contain the incident and has since implemented additional verification protocols to prevent similar attacks. The firm also advised customers to remain vigilant for phishing attempts and to monitor their accounts for any unusual activity.
The attackers exploited trust in official government communication channels by mimicking legitimate correspondence. Revolut acknowledged that its internal processes failed to adequately verify the authenticity of the requests before releasing data. The company is now working with cybersecurity experts to strengthen its request validation systems.
What Are the Broader Implications?
This incident underscores the growing sophistication of social engineering attacks targeting financial institutions. Regulators may scrutinize Revolut's data handling practices, and the firm could face compliance reviews under existing data protection laws.
Revolut has not disclosed the total number of affected customers but confirmed that all impacted users have been contacted directly. The company expects to complete its full investigation within the coming weeks and will provide updates as necessary.
What type of data was compromised? Personal identity and contact information, including birth dates, addresses, emails, and phone numbers. No financial credentials were exposed.
Frequently Asked Questions
How did the breach occur? Fraudsters sent fake data requests that appeared to come from a legitimate government email domain, tricking Revolut into releasing customer information.
What should affected customers do? Customers should watch for suspicious messages and report any unusual account activity. Revolut has already notified all impacted users directly.
More stories: