Photo by Miguel Á. Padriñán on PexelsRevolut has confirmed that sensitive customer data, including IDs and financial information, was disclosed for nearly 700 customers following a sophisticated social engineering attack. The London-based banking platform clarified that customer funds were not affected and this was not an intrusion into its systems.
The breach occurred when Revolut accepted fraudulent information requests from an email address on what appeared to be a legitimate government agency domain. According to Malwarebytes, this was an “external impersonation scam” rather than direct access to Revolut’s internal systems. The criminals exploited the trust associated with a real government email domain to make bogus demands for customer information. Reuters reported that the incident involved “fake government requests”.
Malwarebytes detailed that the attackers obtained “sensitive customer records”, specifically “IDs and other exposed information” which could lead to identity theft. While a “limited” or “very limited” number of customers were affected, the Financial Times specified that “nearly 700 customers’ data” was handed over to the scammers. Revolut has directly contacted those customers, providing specifics on which personal data was disclosed.
Upon detecting the activity, Revolut promptly blocked the sending address and alerted the relevant government agency, law enforcement, data protection authorities, and financial regulators. The company stresses that customer funds remain secure, with the likely consumer impact being second-stage fraud attempts rather than immediate unauthorised transfers. Staying informed about such incidents highlights Why Cybersecurity Awareness Matters More Than Ever.
Revolut has issued guidelines to help customers protect themselves from potential follow-up scams:
Comments are off for this post.