Revolut confirms data breach via fake government email requests
Revolut has confirmed a data breach in which sensitive customer information was disclosed to an unauthorized third party following fraudulent requests sent from a legitimate government email domain. The exposed data includes personal identifiers such as birth dates, addresses, phone numbers, and copies of passports and driver’s licenses, as well as verification selfies and transaction histories. The company said only a “limited” number of customers were affected and that it has contacted them directly. Revolut blocked the compromised email address, notified authorities, and emphasized that customer funds and systems remain secure. The breach comes as Revolut expands globally and prepares for a potential public listing valued at up to $200 billion. Security researcher ZachXBT noted that high-net-worth users appeared to be the main targets. The incident underscores the growing sophistication of impersonation scams exploiting trusted government domains.
Read the full story on TechCrunch →