
![]()
Revolut, the fintech company, is believed to have identified approximately 680 customers affected by a recent data breach.
The company has provided little detail about the extent of the data breach, stating only that a “very limited” number of customers were impacted. It said all affected customers have been notified.
The data reportedly exposed in the breach included customers’ dates of birth, postal and email addresses, telephone numbers, and copies of identity documents such as passports and driving licences.
Customers’ verification selfies, taken when opening an account, were also reportedly compromised.
Overall, around 680 customers are understood to have been affected, including 12 based in Ireland.
A Revolut spokesperson said via The Journal: “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators. Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support," the spokesperson added.
Cybersecurity firm ESET Ireland told the Journal that it is concerned about how the leaked information could potentially be exploited in the future.
It stated that the amount of personal data held by Revolut could allow scammers to pose as legitimate members of the company’s fraud team, or impersonate staff from other organisations or agencies, potentially enabling further fraud against affected customers.
There are also concerns that the stolen information could be used to open accounts or apply for credit in victims’ names.