Exposed data includes customers’ identity and contact details.
Irish people are among those whose sensitive information was disclosed after Revolut mistakenly gave data to scammers, the Irish Independent has confirmed.
It is understood that 680 customers globally have been affected by the data breach, and 12 of those are Irish.
The fraudsters claimed they were from a government agency and were given access to the data.
The exposed data includes customers’ identity and contact details.
It also included dates of birth, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to TechCrunch reported the breach Saturday.
It was reported that the exposed data included customers IBANs.
TechCrunch’s report added that a notification emailed to impacted customers said personal identity documents, such as passports and driver’s licenses, were also shared.
Asked repeatedly exactly what data was disclosed, Revolut would not say.
However, it is now understood that the Irish Central Bank and the Irish Data Protection Commission
One Dublin-based woman whose account was impacted told the Irish Independent she was now locked out of her account. She said this was extremely annoying.
She said she was lucky this has not left her unable to access to money as she also has an AIB current account.
Revolut insisted it had not been hacked.
“Our core infrastructure, databases, and customer accounts were not hacked. The issue involved an external party using an official government agency email domain to send information requests,” it said.
The fintech said a “limited number” of individuals were impacted by the breach and these customers have been contacted directly.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” Revolut said.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”
It appears that scammers used a legitimate government email domain seeking data from Revolt.
The financial technology firm said it blocked the address after detecting the scheme and alerted the “relevant government agency,” law enforcement, data-protection officials and financial regulators.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators. Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support.”
Revolut said financial institutions are legally required to comply with official law enforcement or government agency requests, meaning communications originating from verified government domain addresses are processed as mandatory legal demands.
Revolt said because the requests carried valid technical domain authentication, they were fulfilled as standard legal compliance under the reasonable expectation that it was an authentic agency inquiry.
It insisted the “incident involved a very limited group of customers”.
Rapidly-expanding Revolut claims to have 3.4 million customers in Ireland.
It says it has more than 80 million customers globally.
Revolut recently disclosed its lending service in Ireland has surpassed €1bn, with the bank providing credit across 300,000 facilities, four year after launching Irish credit services.
It appears that scammers used a legitimate government email domain seeking data from Revolut.
The financial technology firm said it blocked the address after detecting the scheme and alerted the “relevant government agency”, law enforcement, data-protection officials and financial regulators.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators. Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support.”
Revolut said financial institutions are legally required to comply with official law enforcement or government agency requests, meaning communications originating from verified government domain addresses are processed as mandatory legal demands.
Revolt said because the requests carried valid technical domain authentication, they were fulfilled as standard legal compliance under the reasonable expectation that it was an authentic agency inquiry.
It would not say how many Irish customers, or customers in other countries, were impacted by the data breach. But it insisted the “incident involved a very limited group of customers”.
Rapidly-expanding Revolut claims to have 3.4 million customers in Ireland. It says it has more than 80 million customers globally.
Revolut recently disclosed its lending service in Ireland has surpassed €1bn, with the bank providing credit across 300,000 facilities, four years after launching Irish credit services.
The incident comes as Revolut reportedly looking at a potential public listing that could value it at as much as $200bn.
It has committed to invest $500m in the US between three to five years. In September, Revolut secured conditional approval to operate as a national bank in the US.

