Data breaches

Revolut: forged government requests exposed customer information

Revolut told Reuters that customer data was disclosed to an unauthorised party after fraudulent requests from a legitimate government agency email domain.

Conceptual illustration: Revolut: forged government requests exposed customer information
Conceptual illustration · SecurCheck

What is confirmed

In a statement to Reuters on 12 September, Revolut said it notified affected customers and blocked the address. It described a 'very limited' number of customers without giving an exact figure in that statement.

Revolut said its systems and customer funds were unaffected. Detailed data categories reported elsewhere should be distinguished from that confirmation.

What it means

The reported scenario involves forged requests sent to the company, not proof that each Revolut customer account was hacked.

Disclosed documents or contact information may be used in future impersonation attempts. A request that knows your personal details still needs independent verification.

What to do

If you receive a notice, open the Revolut app directly and check its help centre without following a text or call link.

Watch for unexpected requests for documents or codes and verify the caller through official contact details.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Reuters — déclaration de Revolut