Entanglemental News
Entanglemental News

Revolut confirms customer data disclosure after fraudulent government requests

Fraudulent requests sent from a legitimate government-agency email domain led Revolut to disclose identity and contact information, while its systems and customer funds remained unaffected.

NEWS AUDIO

Listen to this article

Ready to listen

Revolut confirmed that sensitive customer information was disclosed to an unauthorized third party after the company received fraudulent information requests from a legitimate government-agency email domain. The incident exploited the apparent authority of an external communication channel rather than a reported intrusion into Revolut’s core systems.

The company described the affected group as a very limited number of customers and said each had been notified. It did not disclose an exact count, so the scope should not be converted into a larger or more precise figure without additional confirmation.

Reported exposed information included dates of birth, postal and email addresses, telephone numbers and copies of identity documents such as passports and driver’s licenses. These categories can support impersonation and targeted phishing, even without access to customer funds.

Revolut said its systems and customer money were unaffected. That distinction limits the confirmed operational impact, but it does not remove the privacy risk created when durable identity documents and contact details reach an unauthorized recipient.

After detecting the incident, the company said it blocked the address used for the requests. It also notified the relevant government agency, law-enforcement bodies, data-protection authorities and financial regulators, placing both the deceptive request channel and Revolut’s verification controls under scrutiny.

The episode highlights a form of security failure that can bypass technical perimeter defenses. A message can originate from a legitimate domain and still contain an unauthorized request, requiring organizations to validate the requesting person, legal authority, scope and independent contact path before releasing data.

The breach comes as Revolut considers a potential public listing and reportedly seeks a valuation of as much as $200 billion. Those corporate ambitions are separate from the incident, but regulatory response, remediation costs and customer trust can affect the governance assessment of a financial-technology company.

The next evidence should include the confirmed number of customers, the full data inventory, the duration of the request activity and any demonstrated misuse. Until those facts emerge, the defensible conclusion is a serious but limited disclosure, with no confirmed compromise of Revolut’s systems or customer funds.