Revolut Users’ Identity and Financial Data Exposed in Impersonation Scam
Share
Revolut has notified a subset of its users that sensitive personal and financial information was compromised during a sophisticated impersonation attack.
The London-based fintech company revealed that an unauthorised third party, posing as a government agency, successfully submitted fraudulent requests for user data. The attackers reportedly utilised a legitimate government agency domain email, which carried valid technical credentials, causing the requests to be treated as authentic inquiries.
Exposed Personal and Financial Data
The compromised information includes a wide range of personally identifiable information (PII) and financial records. According to Revolut, the exposed data includes names, addresses, phone numbers, email addresses, dates of birth, and occupations.
More critically, the breach involved highly sensitive identity documents, including copies of driver’s licenses, passports, and verification selfies. Financial details were also exposed, comprising IBANs, account statements, withdrawal records, and full transaction histories, including Bitcoin movements.
This incident follows previous disclosures from Revolut regarding the exposure of identity and financial data.
Company Response and Mitigation
A spokesperson for Revolut confirmed the incident, stating that the company immediately blocked the attacker’s email address upon discovery. The neobank has also notified relevant law enforcement, financial regulators, and data protection authorities.
While Revolut has not disclosed the exact number of individuals affected, the company emphasised that only a subset of its 80 million users was impacted. Revolut stated that its core systems and customer funds remain unaffected and that the company is providing direct support to the impacted individuals.




Leave a Reply