In section Startups & Technology

Revolut Suffers Data Breach From Fraudulent Official Emails

A sophisticated impersonation scam allowed an unauthorized third party to extract sensitive customer data from Revolut by masquerading as a legitimate government agency. The fintech confirmed that attackers bypassed security protocols using an official email domain, compromising identity documents and private financial records of an undisclosed number of global users.

Revolut Suffers Data Breach From Fraudulent Official Emails

The breach exposed extensive personal information, including passports, driver’s licenses, birth dates, and contact details. In some instances, the unauthorized party accessed account statements, transaction histories, and verification selfies. While the firm insists that its core systems and customer funds remain secure, it has refused to clarify how many individuals were targeted or which government entity was exploited in the attack.

Security researcher ZachXBT noted that the campaign appeared to target high-net-worth clients, a claim that complicates the narrative for the London-based company as it pursues a potential public listing. With over 80 million users and recent banking license approvals in Europe and the U.S., Revolut faces mounting pressure to demonstrate robust security controls. The company stated it has blocked the malicious email address and notified relevant law enforcement and regulatory bodies regarding the incident.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!