British fintech giant Revolut has confirmed a data breach where sensitive user information was disclosed to a third party impersonating a government agency. The breach included highly sensitive identity and transaction records.

  • Revolut confirmed a subset of users had personal and financial data exposed.
  • Attackers used a legitimate government agency domain to pose as authorities.
  • Exposed data includes passports, driver's licenses, and full transaction history.
  • Revolut states that customer funds and core systems remain unaffected.

London-based fintech leader Revolut is notifying a segment of its massive user base that their sensitive personal and financial information has been compromised. The breach occurred during a sophisticated impersonation scam where an unauthorized third party successfully posed as a government agency.

According to reports, the attackers utilized valid technical domain credentials, making their fraudulent request appear as an authentic inquiry from a regulatory or law enforcement body. Because financial institutions are legally obligated to comply with legitimate government requests, the breach bypassed standard verification protocols.

Detailed Scope of the Breach

The scale of the data exposure is significant, touching upon both identity and financial privacy. The compromised data points include:

  • Personally Identifiable Information (PII): Names, physical addresses, phone numbers, email addresses, dates of birth, and occupations.
  • Identity Verification Documents: Digital copies of driver’s licenses, passports, and verification selfies used for KYC processes.
  • Financial Records: IBANs, account statements, withdrawal logs, and a comprehensive transaction history, including cryptocurrency/Bitcoin movements.

BozokMedia analysis shows that this was not a simple brute-force hack but a highly targeted social engineering attack that weaponized the institutional trust required by law.

This incident highlights a growing trend where attackers exploit the legal compliance mandates of financial institutions to gain unauthorized access.

Why This Matters

With over 80 million users across 160 countries, Revolut is a cornerstone of the global fintech ecosystem. While the company maintains that only a limited subset of users was impacted and that customer funds are secure, the exposure of identity documents like passports and selfies poses a long-term risk of identity theft and sophisticated phishing attacks.

Historical Background

The rise of neobanks has shifted the cybersecurity landscape. Traditional banks have long-standing physical verification methods, but fintechs rely heavily on digital identity verification (KYC). This reliance on digital-first credentials has made them prime targets for advanced impersonation scams that mimic regulatory communications.

Did You Know?: Identity theft involving 'verification selfies' is particularly dangerous because it can be used to bypass biometric security measures on other digital platforms.

Frequently Asked Questions

1. Is my money safe in my Revolut account?
Yes, Revolut has explicitly stated that their systems and customer funds are unaffected by this breach.

2. How can I protect myself from similar scams?
Always verify the source of any request for information through official channels and enable multi-factor authentication (MFA) on all financial accounts.