London-based banking and financial platform Revolut has confirmed a data breach following an external impersonation scam, which led to the disclosure of sensitive customer records.
The incident, described by Revolut as an external impersonation scam rather than an intrusion into its systems, saw the company accept fraudulent information requests. These requests were sent from an email address on a legitimate government agency domain, according to Malwarebytes. Revolut has not identified the specific government agency involved.
What Customer Data Was Compromised?
While Revolut states that customer funds were not affected, the criminals obtained customer IDs and financial data through this social engineering attack. Reports indicate that Revolut handed over data belonging to nearly 700 customers to these scammers.
Revolut has stated that a “limited” or “very limited” number of customers were impacted and has contacted them directly. Those affected have received, or will receive, an email detailing precisely which of their personal data was disclosed.
Implications for Oxfordshire and UK Customers
The likely impact for affected customers in Oxfordshire and across the UK will be second-stage fraud attempts, rather than immediate unauthorised transfers. Disclosed IDs and other information could be used for identity theft.
Revolut advises customers to treat any unexpected contact claiming to be from the company as suspicious. This includes calls, emails, WhatsApp messages, or text messages that ask users to “secure” an account, reverse a transfer, or replace documents. Customers should avoid using links or phone numbers provided in such messages. Instead, if there are concerns, contact Revolut directly through official channels, such as the secure in-app chat.
It is also recommended that customers monitor their accounts and credit reports for any unfamiliar account openings or credit applications. If you received a notification email from Revolut, it is crucial to check your balances, cards, beneficiaries, recent transfers, account statements, and linked devices, reporting any unfamiliar activity immediately.
Revolut’s Response to the Breach
Upon detecting the fraudulent activity, Revolut immediately blocked the sending address. The company also notified the relevant government agency, law enforcement agencies, data protection authorities, and financial regulators about the incident.