AI

Revolut Acknowledges Customer Data Breach Linked to Fraudulent Government Requests

Revolut, a notable British fintech company, has acknowledged a breach that resulted in the exposure of sensitive customer data to an unauthorized entity following fraudulent requests made using a legitimate governmental email domain.

The compromised information included various personal identifiers, such as customers’ names, birth dates, postal and email addresses, and phone numbers. Additionally, it contained copies of identification documents, such as passports and driver’s licenses. Reports imply that the leaked data may have also encompassed verification selfies, account statements, and transaction records, as outlined in a notification sent to the impacted customers.

A spokesperson for Revolut confirmed to TechCrunch that only a “limited” subset of customers was affected and indicated that the company had reached out directly to those involved. However, the company refrained from disclosing the precise number of individuals impacted or specifying if the incident was confined to certain markets. They also did not reveal the identity of the governmental agency implicated.

“Revolut recently identified a sophisticated external impersonation scam that involved an unauthorized party utilizing an authentic government agency’s email domain to make fraudulent information requests,” the spokesperson stated.

After uncovering the scam, Revolut reported that it has blocked the email address used by the unauthorized party and has informed the appropriate government agency, law enforcement, and regulators, asserting that “Revolut systems and customer funds are unaffected.”

Revolut, headquartered in London, boasts over 80 million global customers and operates as a banking institution in more than 30 nations. The company has recently broadened its presence in markets like India, Mexico, France, and the UAE. Additionally, earlier this month, it received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank, aiming for a launch in the first half of 2027.

Prominent crypto security expert ZachXBT highlighted Revolut’s notification to affected customers late on Friday, noting that the incident seemed particularly aimed at high-net-worth individuals.

This breach occurs as Revolut is reportedly considering a public offering that could elevate its valuation to approximately $200 billion, a significant increase from its $75 billion valuation in November. The fintech has also been actively expanding its banking operations across Europe and globally, recently securing banking licenses in both France and the UK.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button