Digital banking provider Revolut has officially confirmed a data breach resulting in the exposure of customer personal information, triggered by fraudulent requests masquerading as government agencies. The incident occurred as attackers successfully bypassed corporate security processes by mimicking legitimate data disclosure requests from law enforcement and administrative bodies.
This announcement is not related to a product or feature update, but rather serves as an official report on a security incident. Revolut has notified affected customers and stated that it is actively investigating the extent of the damage and implementing countermeasures.
Unlike attacks that exploit direct technical vulnerabilities, this method represents a sophisticated form of social engineering that abuses standard operating procedures. By cleverly forging government credentials, the perpetrators circumvented the company's routine data-sharing workflows, highlighting critical new challenges in authentication practices across digital platforms.
Revolut is urgently strengthening its authentication protocols to identify and block unauthorized requests, while also overhauling verification processes for inquiries from external bodies. Moving forward, the company maintains its commitment to prioritizing customer data protection through enhanced monitoring and ongoing initiatives to prevent the recurrence of similar incidents.