Revolut Discloses Customer Data Breach Following Domain-Spoofing Scam
The banking sector faces heightened scrutiny following a major customer data breach at Revolut, driven by a sophisticated domain-spoofing scam. This incident presents significant operational and reputational risks for the British fintech firm, coming at a pivotal moment as the company prepares for an initial public offering (IPO) with an estimated valuation of $200 billion.
Image: Allison Saeng/Unsplash
According to a Reuters report, cybercriminals successfully breached the digital banking platform Revolut by exploiting a legitimate government email domain. This unauthorized access resulted in the exposure of highly sensitive customer identification data. The security incident occurs at a critical juncture for the British fintech firm, which is currently pursuing a public listing with a projected $200 billion valuation.
London-based Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries.
Revolut confirmed that sensitive customer information was disclosed to an unauthorized third-party following fraudulent requests originating from a legitimate government agency email domain. This security failure could potentially complicate the firm’s reputation and intensify regulatory scrutiny during its valuation process.
A subsequent TechCrunch report said the compromised data included customers’ birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses.
The stolen data also exposed government-issued IDs (passports and driver’s licenses) alongside dates of birth significantly elevates the risk of severe identity theft for the affected users.
However, Revolut said in a statement that the breach affected a “very limited” number of customers, who had been notified by the company. It did not give further details.
The breach highlights a critical vulnerability where attackers didn’t hack the system directly; instead, they used a compromised or spoofed legitimate government email domain to trick the company into handing over data.
“The @Revolut data leak drives home a point I have been making for years due to my work with @inca_digital that most don’t want to acknowledge: banks and regulators are deeply unprepared for the modern shape of fraud,” wrote Austin Campbell, Founder, Zero Knowledge, in a post on X.
According to the local 7dimanche newspaper in Wallonia, the breach includes Belgian users, who couldn’t determine the scope of the breach (many did not receive a disclosure email).
Per Article 15 of the GDPR, a Subject Access Request (SAR) allows individuals to ask a data controller if their personal data is being processed, obtain a copy of that data, and receive key details about how it is used.
Revolut customers who did not receive an email notification about this incident, may write to the Data Protection Officer, Revolut Ltd. at: [email protected] – mentioning their account number/IBAN, phone number and email ID.
