CyberSecurity Alert | Revolut Data Breach

Edited

You may have seen news coverage of a data breach at Revolut. We're reaching out because of what this incident exposed, and because we want to be upfront about what we do and don't know, rather than wait until we have a complete picture.

What happened

Revolut has confirmed that an attacker impersonated a government agency, using that agency's real email domain, to trick Revolut into handing over customer data. The exposed information can include identity documents (passports and driver's licenses), verification selfies, addresses, dates of birth, account statements, and full transaction histories. In the last day or two, the attackers have begun publicly posting some of this material on X and Telegram, and are threatening to keep releasing more.

What we don't know yet

Revolut has only said a "limited" number of customers were affected and hasn't published a number, a list, or which countries were involved. That means we can't tell you definitively whether you personally are in the exposed set, and neither, publicly, can Revolut. 

What we recommend

  • If you use Revolut, let us know so we can factor it into our monitoring; we're watching for anything related to this incident to the best of our abilities. 

  • Treat communication with caution: If you receive an email or message from Revolut about this breach, treat it with real caution before clicking anything: verify it through Revolut's official app or website directly rather than any link in the message, as opportunistic phishing using this same news story is a real possibility. 

  • Confirm directly: If you haven't heard from Revolut directly, but want to know your account's status, you can reach out to Revolut support and ask them directly whether you're among the affected customers. 

We'll follow this story as more details come out and reach back out if anything changes that affects you specifically.