Newsroom
Revolut has suffered a data breach after fraudsters posing as government officials tricked the financial technology company into releasing sensitive customer information.
The incident was not a direct attack on Revolut’s computer systems. Instead, an unauthorized third party reportedly used an email address linked to a legitimate government agency to submit fraudulent requests for customer records.
Believing the requests were genuine, Revolut released information belonging to a limited number of customers.
About 680 customers are understood to have been affected, according to Reuters, although Revolut has not publicly confirmed the precise number or the countries in which those customers live.
There is currently no evidence that any of Revolut’s roughly 450,000 users in Cyprus were among those affected.
The company said it has contacted affected customers directly.
What information was exposed?
The information may include names, dates of birth, email and home addresses, telephone numbers, and workplaces.
In some cases, copies of passports and driving licenses, verification photographs, bank statements, IBANs, and transaction histories may also have been disclosed.
Revolut said it blocked the email address after discovering the scam and notified the government agency involved, as well as law enforcement, data-protection authorities, and financial regulators.
The company stressed that its core infrastructure, databases and customer accounts were not hacked. Customer funds were also unaffected.
Hackers reportedly demand ransom
A group calling itself “iamnotavillain” has claimed responsibility and reportedly threatened to release or sell confidential customer records unless Revolut pays a $3 million ransom in the privacy-focused cryptocurrency Monero.
Revolut, however, said it has received no direct communication or ransom demand from the group.
That means the ransom threat has been made publicly, but the company has not confirmed that the people behind it are responsible for obtaining the customer data.
Why Cyprus users should be cautious
Even when money and passwords are not stolen, exposed personal information can make future scams far more convincing.
A fraudster who knows a customer’s full name, address, date of birth, telephone number, or banking history may be able to pose convincingly as a Revolut employee, police officer, or government official.
Users should be particularly cautious about emails, telephone calls, or text messages asking them to click a link, confirm personal details, share a security code, or move money to a so-called “safe account.”
Revolut will not ask customers to transfer their balance to another account for protection. Anyone receiving a suspicious message should avoid using the links or telephone numbers provided and contact Revolut directly through the official app.
Customers who have not been contacted by Revolut should not assume that their information was exposed. However, with the full list of affected countries still unclear, users would be wise to remain alert for unusually detailed or convincing phishing attempts.
*Sources: Reuters, Revolut statement reported by RTE




























