Revolut confirms customer data breach through fake government requests
British fintech Revolut confirmed a data breach affecting a limited number of customers after it responded to fraudulent requests from an unauthorized third party. The scam involved emails sent from a legitimate government agency domain, leading Revolut to disclose sensitive customer information. Exposed data included identity and contact details, such as birth dates, postal and email addresses, phone numbers, and copies of identity documents like passports and driver’s licenses. The company has notified affected customers and alerted relevant government agencies, law enforcement, and financial regulators. Revolut maintains that its systems and customer funds remain unaffected by the incident.
Revolut's data breach, stemming from a sophisticated impersonation scam using a legitimate government email domain, highlights a growing vulnerability for fintechs operating in Asia. While the exact number of affected customers and markets remains undisclosed, the incident involved sensitive data including identity documents and transaction histories. This type of social engineering attack, leveraging trusted government channels, presents a significant risk to the expanding digital banking sector across India, Mexico, and the UAE, where Revolut has recently broadened its presence. The incident serves as a critical reminder for financial institutions to reinforce their internal protocols against advanced phishing and impersonation tactics. The potential targeting of high-net-worth individuals, as suggested by crypto security researcher ZachXBT, adds another layer of concern. For Asian markets, where digital adoption is rapid and regulatory frameworks are still evolving, such breaches can erode customer trust and invite stricter oversight. The incident underscores the need for robust verification processes beyond email domain legitimacy, especially as fintechs like Revolut pursue aggressive global expansion and potential public listings. The thing to watch is how regulators in markets like India and the UAE respond to this type of breach, which could influence data protection standards for regional fintech players.
Related reading
6 stories
AI Agents: The Double-Edged Sword of Cyberattacks
Our past analysis explored how AI agents, while powerful, also present new vectors for cyberattacks and data breaches.

Anthropic merges Claude chat and Cowork in one interface

Threads’ new features let podcasters promote shows and reach listeners
ViewSonic expands Pro AV portfolio in India with new LED displays, monitors and Google TVs: All details

HKSTP pledges full support for Five-Year Plan and Policy Address to steer I&T growth

