
Revolut Breach: Beware Follow-Up Identity Scams
Revolut told BleepingComputer that a limited number of customers had data disclosed after an attacker impersonated a government agency. The practical risk is convincing follow-up fraud, not evidence that all Revolut accounts were hacked.
The short version
What you need to know
- Revolut says a limited number of customers were affected; an exact count has not been disclosed.
- BleepingComputer reports that exposed data included identity documents, verification selfies and transaction information. Revolut says its systems and customer funds are unaffected.
- Use the independently opened Revolut app to verify any notice. Someone knowing your transactions or personal details does not prove they work for the bank.
What happened
BleepingComputer reported on 14 September that Revolut disclosed customer information to an attacker posing as a government agency. The publication quotes customer notices saying the request arrived by email using a government agency's domain and carried valid domain authentication credentials, leading staff to treat it as genuine.
According to those notices, the disclosed information included identity and contact details, copies of passports or driving licences, verification selfies, account statements including IBANs, withdrawal records and transaction history. This reporting does not establish that every affected person had every type of document exposed.
A Revolut spokesperson told the publication that a limited number of customers were affected and that its systems and customer funds were unaffected. The company said it blocked the address and alerted the relevant agency, law enforcement and regulators. No exact affected-customer count was provided.
Why this matters even if funds are unaffected
A detailed transaction or identity record can make a fraudulent call unusually persuasive. A caller might refer to a genuine payment, your address or an identity document before asking you to approve a login or move money. Treat that knowledge as information they possess, not proof of who they are.
The reported mechanism also matters: an authenticated email domain is not the same as an independently verified, authorised disclosure request. The available report does not identify exactly how the attacker obtained use of the agency domain, so it would be premature to describe a specific government mailbox compromise as established fact.
What customers can do now
Open Revolut through the app you already use and contact support there to verify whether a notice applies to you. Do not use a caller's suggested support link or a phone number supplied in an unexpected breach message. Never share one-time codes or approve a prompt because someone says they are protecting your account.
Review account activity and report unfamiliar transactions through official support. If a notice says identity documents were involved, ask the document issuer through its official channel what incident-specific steps are appropriate; do not assume every customer needs to replace a passport. Keep the notice and records of suspicious contact.
Use unique passwords and the account's available security controls. These are sensible precautions, not a way to retrieve disclosed documents. The reporting does not say that every Revolut password was stolen, nor does it establish that all customers need emergency account changes.
Where a VPN does not help
A VPN protects supported network traffic between your device and its server. It cannot prevent a company from sending stored records to an impostor, erase copies already disclosed or authenticate a caller. For this incident, separate-channel verification and account monitoring are more directly useful than buying another privacy product.
Our guide to what a VPN hides explains that boundary. The earlier scam-text explainer covers a related habit: reach an organisation through a route you already trust rather than a link delivered with an urgent request.
Primary reading
Sources and further reading
We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.