Revolut Discloses Data Breach Exposing Financial Info and Passports for Thousands of Customers
Financial technology company Revolut has revealed that it has been targeted by a sophisticated cyber attack, resulting in the unauthorized disclosure of sensitive customer data. The company, which operates in over 160 countries and serves more than 80 million customers worldwide, including 800,000 businesses, said that a threat actor impersonating a government agency requested personally identifiable information (PII) from an undisclosed number of customers via email.
The attack is particularly concerning because it demonstrates the ability of sophisticated attackers to bypass even basic security protocols. In this case, the attacker’s email carried valid domain authentication credentials, which led Revolut to reasonably believe that it was an authentic government agency request. The company has since acknowledged that this was a mistake and has taken steps to block the attacker’s address and alert relevant authorities.
The data exposed in the breach includes sensitive information such as full names, dates of birth, occupations, contact details, and document verification data, including copies of passports and driver’s licenses. Additionally, account statements, withdrawal records, and full transaction histories were also compromised, including Bitcoin transactions. While Revolut has refused to disclose an exact number of affected customers, the company has acknowledged that it is a limited number.
It is worth noting that this is not the first time Revolut has been targeted by cyber attackers. In 2022, the company disclosed another data breach affecting 50,150 customers. The fact that Revolut has been targeted again raises questions about the company’s cybersecurity posture and its ability to protect sensitive customer data.
Revolut has assured affected customers that their systems and funds are unaffected, but the incident highlights the ongoing threat of sophisticated cyber attacks against financial institutions. As customers, it is essential to remain vigilant and take steps to protect ourselves from potential identity theft and financial losses. In light of this breach, we recommend that all Revolut customers review their accounts for any suspicious activity and consider implementing additional security measures to safeguard their sensitive information.
In a statement, crypto fraud investigator ZachXBT noted that the breach likely targeted high-net-worth users, which raises concerns about the vulnerability of wealthy individuals to cyber attacks. The incident serves as a reminder to all financial institutions to prioritize cybersecurity and take proactive measures to protect sensitive customer data from sophisticated attackers. As we continue to navigate an increasingly complex threat landscape, it is essential for companies like Revolut to stay ahead of emerging threats and ensure the security of their customers’ information.
Source: Bleeping Computer — 2026-09-14