Revolut Data Breach: What UK Customers Need to Know

Revolut has confirmed that sensitive customer data, including IDs and financial information, was disclosed for nearly 700 customers following a sophisticated social engineering attack. The London-based banking platform clarified that customer funds were not affected and this was not an intrusion into its systems.

What Happened in the Breach?

The breach occurred when Revolut accepted fraudulent information requests from an email address on what appeared to be a legitimate government agency domain. According to Malwarebytes, this was an “external impersonation scam” rather than direct access to Revolut’s internal systems. The criminals exploited the trust associated with a real government email domain to make bogus demands for customer information. Reuters reported that the incident involved “fake government requests”.

Customer Data at Risk and Revolut’s Response

Malwarebytes detailed that the attackers obtained “sensitive customer records”, specifically “IDs and other exposed information” which could lead to identity theft. While a “limited” or “very limited” number of customers were affected, the Financial Times specified that “nearly 700 customers’ data” was handed over to the scammers. Revolut has directly contacted those customers, providing specifics on which personal data was disclosed.

Upon detecting the activity, Revolut promptly blocked the sending address and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators. The company stresses that customer funds remain secure, with the likely consumer impact being second-stage fraud attempts rather than immediate unauthorised transfers. Staying informed about such incidents highlights Why Cybersecurity Awareness Matters More Than Ever.

Advice for Revolut Customers

Revolut has issued guidelines to help customers protect themselves from potential follow-up scams:

  • Be Suspicious of Unexpected Contact: Treat any unsolicited Revolut-related contact—especially calls, emails, WhatsApp messages, or text messages—as suspicious. This includes messages claiming you need to “secure” an account, reverse a transfer, or replace documents.
  • Avoid Links and Provided Numbers: Do not use links or phone numbers supplied in suspicious messages. Instead, end contact with suspected scammers and reach out to Revolut directly through official channels, such as their secure in-app chat.
  • Monitor Accounts and Credit: Given that IDs and other exposed information could be used for identity theft, customers should monitor their bank accounts and credit reports for unfamiliar account openings or credit applications. Considering a fraud alert or credit monitoring service where available is advisable.
  • Check Account Activity: If you received a notification email from Revolut regarding the breach, carefully check your balances, cards, beneficiaries, recent transfers, account statements, and linked devices. Report any unfamiliar activity immediately via Revolut’s secure in-app chat. Awareness of evolving threats, as discussed in Why Cybersecurity Threats Are Rising Worldwide, is crucial for personal financial security.


Comments are off for this post.

Latest Posts

Latest

More
More

You Might Also Like