British fintech company Revolut is under regulatory investigation in the UK due to a customer data breach incident. Multiple foreign media reports indicate that attackers used emails with domain names of legitimate government agencies to send fraudulent requests for information. Revolut initially treated these as legitimate requests and later issued risk notifications to approximately 680 customers.
Using a government email address to initiate requests
This incident was not due to a breach in the Revolut system itself, but rather a third party impersonating a government agency and soliciting customer information through what appeared to be legitimate official channels. Revolut described this as a "complex external impersonation scam" and stated that customer funds and the company's systems were not affected.
The company stated that after discovering the anomaly, they have blocked the relevant email addresses and notified the involved government agencies, law enforcement departments, data protection organizations, and financial regulatory authorities. However, Revolut has not yet made public the verification processes that were conducted internally for these fraudulent requests.
Leaked information includes identity documents and Bitcoin transaction records.
Foreign media revealed customer notifications indicating that the potentially leaked information covers a wide range of details, including names, dates of birth, occupations, addresses, email addresses, phone numbers, as well as copies of passports or driver's licenses, and identity verification selfies.
In terms of financial information, relevant records may also include account statements, IBAN, account opening dates, account status, withdrawal records, and a complete transaction history. For users of crypto assets, the leaked information also involves Bitcoin transaction records and the wallet reference numbers displayed in their accounts.
However, the existing information does not indicate that private keys, account passwords, or complete bank card details have been handed over to unauthorized parties. The notification lists categories of information that 'may be involved', which does not mean that every affected customer has had all their information leaked.
British regulators have launched an investigation
The UK Information Commissioner's Office (for token issuance) has launched an investigation following a proactive report at Revolut. The investigation itself does not necessarily mean that the regulatory authorities have determined that Revolut has violated UK data protection laws, but whether the incident involves improper data processing will become a focus of subsequent attention.
It is reported that individuals claiming to be involved in the incident have threatened to disclose public customer information in exchange for payment of Revolut. Some of this information was disseminated through the Telegram account, but some of the claims have not yet been independently verified.
Revolut has not yet made public the name of the government agency involved, nor has it explained how that email account was compromised. The company recently obtained permission to operate as a full-fledged British bank, and this incident has also put its data security and compliance processes under greater scrutiny.












