Key facts
- Revolut disclosed sensitive customer information to an unauthorized third party.
- The breach occurred after fraudulent requests were sent from a legitimate government agency email domain.
- Exposed data includes identity and contact details, birth dates, addresses, and phone numbers.
- Copies of identity documents, verification selfies, account statements, and transaction histories may have been compromised.
- Revolut confirmed a "limited" number of customers were impacted and has contacted them directly.
- Revolut stated its systems and customer funds are unaffected.
British fintech Revolut has confirmed a data breach where sensitive customer information was disclosed to an unauthorized third party. The incident occurred after a scammer used a legitimate government agency email domain to submit fraudulent requests for information. The exposed data includes customer identity and contact details such as birth dates, postal and email addresses, and phone numbers. Additionally, copies of identity documents like passports and driver's licenses, verification selfies, account statements, and transaction histories may have been compromised.
