Revolut claims only a small number of customers impacted
Irish people are understood to be among those whose sensitive information may have been disclosed after Revolut mistakenly gave data to scammers.
The bank handed information to fraudsters who claimed they were from a government agency and were given access to the data.
Highly sensitive data exposed in the leak included customers’ identity and contact details.
It also included dates of birth, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driving licences, according to TechCrunch which first reported the breach on Saturday.
It was reported that the exposed data included customers IBANs.
TechCrunch’s report added that a notification emailed to impacted customers said personal identity documents, such as passports and driver’s licenses, were also shared.
Asked repeatedly what exactly what data was disclosed, Revolut would not say. It also did not reply when asked if it has informed the Irish Central Bank about the data breach.
One Dublin-based woman whose account has been hacked told the Irish Independent she was now locked out of her account. She said this was extremely annoying.
She could not confirm whether the incident was a result of the data breach or a separate incident.
She said she was lucky this has not left her unable to access to money as she also has an AIB current account.
Revolut insisted it had not been hacked.
“Our core infrastructure, databases, and customer accounts were not hacked. The issue involved an external party using an official government agency email domain to send information requests,” it said.
The fintech said a “limited number” of individuals were impacted by the breach and these customers have been contacted directly.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” Revolut said.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”
It appears that scammers used a legitimate government email domain seeking data from Revolut.
The financial technology firm said it blocked the address after detecting the scheme and alerted the “relevant government agency,” law enforcement, data-protection officials and financial regulators.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators. Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support.”
Revolut said financial institutions are legally required to comply with official law enforcement or government agency requests, meaning communications originating from verified government domain addresses are processed as mandatory legal demands.
Revolt said because the requests carried valid technical domain authentication, they were fulfilled as standard legal compliance under the reasonable expectation that it was an authentic agency inquiry.
It would not say how many Irish customers, or customers in other countries, were impacted by the data breach. But it insisted the “incident involved a very limited group of customers”.
Rapidly-expanding Revolut claims to have 3.4 million customers in Ireland.
It says it has more than 80 million customers globally.
Revolut recently disclosed its lending service in Ireland has surpassed €1bn, with the bank providing credit across 300,000 facilities, four year after launching Irish credit services.
The incident comes as Revolut reportedly looking at a potential public listing that could value it at as much as $200bn.
It has committed to invest $500m in the US between three to five years. In September, Revolut secured conditional approval to operate as a national bank in the US.

