Revolut Exposed Customer Data After Falling for Fake Gov Email
Revolut accidentally handed over sensitive customer data — including passports — after staff were tricked by a convincing fake government email. Here's what it means for your account.
What happened
Revolut suffered a data breach after employees were deceived by a fraudulent request that appeared to originate from a legitimate government email domain, according to Finextra. Staff complied with the request and inadvertently handed over sensitive customer information, reportedly including passport details. The incident is a textbook case of social engineering — manipulating people rather than hacking systems directly. Revolut has not yet publicly disclosed exactly how many customers were affected.
Why it matters
This breach is notable precisely because it bypassed technical defences entirely. Even a large, well-resourced fintech with sophisticated security infrastructure can be undone by a convincing email that exploits trust in official-looking senders. Social engineering attacks have been rising across the financial sector, and fintechs — which hold a dense concentration of identity and payment data — are high-value targets. The incident also raises questions about internal verification procedures when third parties request customer data.
Impact on personal finance
If you are a Revolut customer, it is worth checking whether you have received any breach notification from the company, and taking that communication seriously if it arrives. Exposed passport data is particularly sensitive because it can be used in identity fraud — for example, opening accounts or taking out credit in your name. It is a good idea to monitor your credit file for any unusual activity in the coming weeks and months. Consider also whether you have reused passwords or security answers across other services, since combined data leaks can amplify the risk. Revolut users concerned about account security can review active sessions and connected devices directly in the app.
Regional perspective
EU/UK: Revolut operates under both UK and EU financial licences, meaning data protection regulators in both jurisdictions — the UK ICO and relevant EU authorities — could investigate. Under GDPR rules, companies can face significant fines for failing to protect personal data adequately, and affected customers have the right to request information about what data was disclosed.
Run these numbers on your own money
Treziqo shows you where your money actually goes, when a cash-flow gap is coming, and what to do about it. Budgets, debts, investments and receipts in one place.
No spam. Just launch info and beta access notifications. Unsubscribe anytime.
This article is for informational purposes only and does not constitute investment or financial advice. It was created with AI assistance under human editorial review, drawing on publicly available sources listed below.
Sources
-
1
Revolut hit by data breach after fake government email scamFinextra — Retail Banking ·
- 2
-
3
Christine Lagarde: A new age of capital: growth, sovereignty and AIECB Press Releases ·
-
4
Piero Cipollone: The future of euro cash: trusted today, designed for tomorrowECB Press Releases ·
-
5
Máte poslední možnost požádat o zasílání valorizačního oznámení na papířeMěšec.cz — Osobní finance ·
-
6
Merchants call on judge to reject Visa-Mastercard interchange fee settlementFinextra — Payments ·