Revolut discloses data breach exposing financial info, passports
Fintech company Revolut has disclosed a data breach after a threat actor, impersonating a government agency via email, obtained sensitive customer data, including identity documents and financial information.
Intelligence analysis by Gemini 2.5 Flash

Revolut, a global fintech firm serving over 80 million customers, fell victim to a sophisticated social engineering attack. An unauthorized email, appearing to originate from an official government agency's domain, tricked the company into releasing personally identifiable information (PII), financial records, and copies of identity documents like passports and driver's licenses for a…
Imagine a sneaky trickster pretending to be a grown-up from the government, sending an email to a big money company called Revolut. Because the email looked super real, Revolut accidentally gave the trickster some secret papers about a few of its customers, like their names, birthdays, where they live, and even copies of their passports and how much money they have. It's like someone pretending to be your teacher and getting your report card from the school office.
Analysis
The recent data breach at Revolut underscores the evolving sophistication of cyber threats, particularly those leveraging social engineering. The incident involved a threat actor successfully impersonating a government agency through an email sent from what appeared to be an official domain. Revolut stated that the communication carried "valid domain authentication credentials," leading them to believe it was an authentic request. This method bypasses many traditional technical defenses, relying instead on human trust and the perceived legitimacy of the sender, making it a challenging vector to defend against.
Government Impersonation
The core of the Revolut breach lies in the attacker's ability to convincingly impersonate a government agency. By using an "unauthorised email account sent directly using the official government agency's email domain," the threat actor exploited a critical vulnerability in Revolut's verification process. The company's statement that the communication carried "valid domain authentication credentials" suggests that the email passed initial legitimacy checks, likely due to compromised credentials or a sophisticated spoofing technique that mimicked the agency's domain. This incident serves as a stark reminder that even with technical safeguards, the human element remains a significant target for attackers, especially when requests appear to come from authoritative sources.
Customer Data
The scope of the exposed customer data is particularly concerning, encompassing a wide array of highly sensitive information. This includes identity details such as full name, date of birth, and occupation, alongside contact details like postal address, email, and telephone number. More critically, the breach exposed document and verification data, specifically copies of identity documents like passports and driver's licenses, as well as facial verification images used for Know Your Client (KYC) processes. Furthermore, account statements, IBAN numbers, withdrawal records, and full transaction histories, including Bitcoin transactions, were compromised. Such a comprehensive data set significantly increases the risk of identity theft, targeted phishing, and financial fraud for the affected individuals.
Revolut's Response
Upon detecting the breach, Revolut claims to have acted swiftly, immediately blocking the malicious address and alerting relevant government agencies, enforcement bodies, data protection authorities, and financial regulators. The company emphasized that its "systems and customer funds are unaffected," aiming to reassure its vast customer base. While Revolut has refused to disclose the exact number of affected customers, stating it was a "very limited" group, crypto fraud investigator ZachXBT suggested the breach might have targeted "high net worth users." This incident is not Revolut's first encounter with a data breach; four years prior, in September 2022, the company disclosed another breach affecting 50,150 customers, where personal, contact, and financial information was stolen. This pattern raises questions about the robustness of Revolut's ongoing security measures and its ability to prevent sophisticated social engineering attacks.
Key points
- Revolut disclosed a data breach caused by a threat actor impersonating a government agency via email.
- The attacker used an unauthorized email account from an official government agency's domain, tricking Revolut into fulfilling the request.
- Exposed data includes full names, dates of birth, occupations, contact details, copies of passports/driver's licenses, facial verification images, account statements, IBANs, withdrawal records, and full transaction history (including Bitcoin).
- Revolut states its systems and customer funds are unaffected and that a "very limited" number of customers were impacted.
- This is Revolut's second data breach in four years, following a similar incident in September 2022 that affected 50,150 customers.
Revolut's swift action in blocking the malicious address and alerting relevant authorities demonstrates a rapid response to contain the incident. The company's assertion that its systems and customer funds remain unaffected, coupled with the "very limited" number of affected customers, suggests the breach's overall impact might be contained.
The exposure of highly sensitive data, including passports and full financial histories, poses a severe risk of identity theft and targeted fraud for the affected individuals, especially if they are high-net-worth users. This incident marks Revolut's second data breach in four years, which could erode customer trust and raise concerns about the company's long-term security resilience against sophisticated social engineering attacks.



