British fintech company Revolut announced on September 12 that a deceptive request, sent from an email address that mimicked a legitimate government agency, resulted in the unauthorized disclosure of sensitive customer information. The breach was discovered by Revolut’s security team, which immediately blocked the malicious address and notified the appropriate government and regulatory bodies.
Details of the breach
According to the company spokesperson, the compromised data includes customers’ birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports and driver’s licenses. The exact number of affected individuals was not disclosed.
Company response and safeguards
Revolut emphasized that its core systems and customer funds were not impacted by the incident. The firm said it promptly alerted the relevant government agency, enforcement agencies, data‑protection authorities, and financial regulators after detecting the fraudulent request. No physical bank branches are part of Revolut’s model, which relies on a digital‑only platform.
Future plans
Despite the breach, Revolut continues to pursue a potential public listing, targeting a valuation of up to $200 billion. The company remains one of Europe’s most successful fintech enterprises, and it has pledged to strengthen its security protocols to prevent similar incidents.
Industry context
Data‑security incidents have become a growing concern for financial technology firms, especially as they handle large volumes of personal and financial information. Experts advise consumers to monitor their accounts for any unusual activity and to consider additional identity‑theft protections when personal documents are exposed.
Original reporting: Appleton, WI News Feed (HLL/CB) — read the source article.