Revolut discloses data breach exposing financial info, passports

Revolut Discloses Data Breach Exposing Financial Info and Passports, Affecting Thousands of Customers Worldwide

A significant data breach has hit fintech company Revolut, exposing sensitive financial information and passport details for thousands of customers. The breach, which occurred when a threat actor impersonated a government agency, highlights the ongoing threat posed by sophisticated phishing attacks.

Revolut operates in over 160 countries and regions, offering banking, money management, and investment services to more than 80 million customers worldwide, including 800,000 business customers. In an email sent to affected customers, Revolut explained that the attacker requested personally identifiable information (PII) via email using a government agency’s domain. The company stated that it fulfilled the request under the reasonable belief that it was an authentic government agency inquiry.

The exposed data includes sensitive information such as identity details, contact details, document and verification data, account statements, withdrawal records, and full transaction history – including Bitcoin transactions. Revolut has refused to disclose an exact number of affected customers but claims it is a limited number. Crypto fraud investigator ZachXBT suggests that the breach may have targeted high net worth users.

The breach highlights the ease with which threat actors can exploit phishing attacks to gain access to sensitive information. Phishing attacks often rely on social engineering tactics, where attackers pose as legitimate entities to trick victims into divulging confidential information. In this case, the attacker impersonated a government agency, using valid domain authentication credentials to convince Revolut that it was an authentic request.

Revolut’s response to the breach has been swift, with the company blocking the threat actor’s address and alerting relevant government agencies, enforcement agencies, data protection regulators, and financial regulators. However, this incident serves as a reminder of the importance of robust security measures in preventing such breaches. Organizations must prioritize authentication processes, implement robust email verification systems, and educate employees on identifying and reporting suspicious emails.

For customers affected by the breach, it is essential to monitor their accounts closely and be vigilant for any unusual activity. Revolut has assured customers that its systems and customer funds are unaffected, but users should still exercise caution when dealing with sensitive financial information online. In light of this incident, it’s crucial to remember that legitimate organizations will never ask for sensitive information via email or phone – no matter how convincing the request may seem.


Source: Bleeping Computer — 2026-09-14