Back to news

Revolut Confirms Customer Information Leak from External Source

According to The Block, Revolut revealed that the company disclosed sensitive customer information to an unauthorized third party.

The third party submitted a fraudulent request for customer records to Revolut using what appeared to be a legitimate government agency email domain. Revolut classified this incident as a "well-planned external impersonation scam."

Revolut stated that after identifying the involved email address, it has blocked it and emphasized that the company's systems and customer funds were not affected.

Revolut mentioned that the number of affected customers is limited, and the company has directly contacted the relevant customers to inform them.

The disclosed information may include customer names, birth dates, mailing addresses, email addresses, phone numbers, and copies of identification documents such as passports and driver's licenses. Additionally, selfies used for identity verification, account statements, and transaction records may also have been leaked.

Such social engineering fraud techniques, like "impersonating government agencies to request records," directly test the ability of fintech platforms to verify customer identities and approve internal data requests. Once strong identity verification materials such as ID documents and selfies are leaked, the risk of affected customers having their identities misused to open accounts, obtain loans, or commit further fraud will significantly increase. For Revolut, while this incident did not involve financial losses, it may raise compliance and customer trust restoration costs in the short term and could prompt other fintech companies to strengthen their verification mechanisms for external data requests.

Source: Public Information

ABAB AI Insight

Revolut has a history of similar security incidents—In September 2022, the company disclosed that it suffered a "highly targeted" cyber attack, resulting in unauthorized access to some personal information of approximately 50,000 customers. The attack method was also classified as a social engineering-induced vulnerability at the employee level, rather than a direct technical system flaw.

As a fintech giant holding banking licenses in multiple countries and valued at several billion dollars, Revolut has been increasing its investments in compliance, risk control, and cybersecurity teams in recent years to support its banking license applications and business expansion in regions like Europe and the United States. This incident occurs at a critical stage as the company seeks to further expand its regulated business landscape and attempt to mitigate its early image of "light compliance, heavy growth." The efficiency of handling this security incident will directly impact its compliance reputation before regulatory agencies.

This is similar to the customer data leak incident disclosed by Coinbase—In early 2025, Coinbase revealed that attackers obtained customer identity information by bribing overseas customer service outsourcing personnel and attempted to extort ransom. Both incidents reflect that the weak links in fintech and crypto platforms are shifting from core system security to customer service processes and identity verification, which are more manipulable human factors.

Essentially, this represents a restructuring of the industry chain—As fintech platforms continue to strengthen their investments in core system security, attackers are shifting their focus from "breaking into systems" to "breaking processes," exploiting gaps in manual approval steps such as customer identity verification and inter-institutional data request responses to commit fraud. This means that the future security investment focus of financial institutions needs to extend from pure technical protection to building social engineering defense capabilities in internal process approvals and employee/customer service interactions.

ABAB News · Cognitive Laws

  1. The harder the system is to breach, the easier the process is to breach.
  2. Impersonating an institution's email is cheaper than hacking a system.
  3. The cracks in customer trust often begin with the approval process.

Source

·ABAB News
·
4 min read
·1 hrs ago
分享: