Download Privacy Needle App

Type to search

Data Breaches

Revolut Users’ Identity and Financial Data Exposed in Impersonation Scam

Share

Revolut has notified a subset of its users that sensitive personal and financial information was compromised during a sophisticated impersonation attack.

The London-based fintech company revealed that an unauthorised third party, posing as a government agency, successfully submitted fraudulent requests for user data. The attackers reportedly utilised a legitimate government agency domain email, which carried valid technical credentials, causing the requests to be treated as authentic inquiries.

Exposed Personal and Financial Data

The compromised information includes a wide range of personally identifiable information (PII) and financial records. According to Revolut, the exposed data includes names, addresses, phone numbers, email addresses, dates of birth, and occupations.

More critically, the breach involved highly sensitive identity documents, including copies of driver’s licenses, passports, and verification selfies. Financial details were also exposed, comprising IBANs, account statements, withdrawal records, and full transaction histories, including Bitcoin movements.

This incident follows previous disclosures from Revolut regarding the exposure of identity and financial data.

Company Response and Mitigation

A spokesperson for Revolut confirmed the incident, stating that the company immediately blocked the attacker’s email address upon discovery. The neobank has also notified relevant law enforcement, financial regulators, and data protection authorities.

While Revolut has not disclosed the exact number of individuals affected, the company emphasised that only a subset of its 80 million users was impacted. Revolut stated that its core systems and customer funds remain unaffected and that the company is providing direct support to the impacted individuals.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.