
Loading

Loading
We use strictly necessary cookies to run this site, and — only with your consent — analytics cookies to understand how it's used. See our Privacy Policy for details.

Revolut has contacted 680 customers believed to have been affected.
Summary
The information reportedly included passport and bank account details. The UK's data watchdog is investigating the incident. A genuine government email address was reportedly used to trick Revolut into handing over sensitive customer information in a data breach that has affected hundreds of people.
The fintech company has contacted 680 customers following the incident, in which a hacker allegedly used a legitimate government email address to send a fraudulent request for private customer information. Revolut reportedly complied with the request before discovering the deception. The information handed over is understood to have included passport details, bank account numbers, home addresses, identity documents, verification photographs and records relating to Bitcoin activity.
The incident has raised questions about how financial firms verify requests for sensitive customer information, particularly when those requests appear to come from an official government address. The UK's Information Commissioner's Office (ICO) said on Monday that it was investigating the breach after Revolut reported the incident to the regulator. When an official-looking request goes wrong Revolut said it “immediately blocked the address” after detecting the issue and notified regulators and customers who may have been affected.
The hackers claiming responsibility for the incident have reportedly threatened to publish the stolen information unless Revolut pays a ransom. Former Mt Gox chief executive Mark Karpelès is among those affected. He said he received an email from Revolut at 5:25am on September 12 warning him that his information could be at risk.
Karpelès has questioned why the information was shared in the first place, arguing that the request should have faced further checks even though it came from a verified government email address. The incident appears to have involved social engineering — a type of cyberattack that relies on manipulating people or organisations into handing over information rather than breaking directly into their computer systems. That distinction matters because it means a company can have security systems in place and still be vulnerable if someone is persuaded that a fraudulent request is genuine.
What Revolut says about customer accounts Revolut has said its systems and customer funds were not affected by the incident. The company has not commented publicly on the reported number of affected customers, although sources have said 680 individuals were contacted. The breach comes as financial companies face growing pressure to protect increasingly large amounts of personal information, from identity documents and addresses to transaction histories.
For customers, the incident raises a more uncomfortable question: if a request appears to come from a genuine government address, how many checks should a financial company carry out before releasing private data? The ICO's investigation is expected to establish what happened and whether Revolut's handling of the request met its obligations for protecting customer information.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
We've archived 1 other article touching the same topic (passport details, revolut, bank account) — see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.