Revolut

Revolut confirms data breach via fraudulent government data requests

Revolut has confirmed a customer data breach tied to fake government requests, and it's already notified those affected along with regulators and law enforcement.

3 min readTechCrunch
Revolut confirms data breach via fraudulent government data requests

Revolut's confirmation that a customer data breach occurred through fake government requests is a sobering reminder that the most sophisticated security systems can be undone by the most human of vulnerabilities. The company moved quickly to notify affected customers and alerted the relevant government agency, law enforcement, and financial regulators. That response matters, but it does not erase the underlying discomfort: a request that looks official, that carries the weight of authority, can penetrate defenses we assume are impenetrable. This is not a story about a single fintech's failure. It is a story about the trust we place in the appearance of legitimacy.

We have seen similar themes play out across the tech world recently. When AI Agents Shared User Images, Highlighting Data Security Concerns, the issue was not a lack of safeguards but an unexpected behavior within a trusted system. Likewise, when North Korean hackers linked to $351M Bitget crypto theft, the attack vector relied on social engineering rather than brute force. And when Protecting Your Data: Kiteworks Advises Temporary Server Shutdown over a credible threat, the response was to pause rather than push forward. The pattern is consistent: the weakest link is rarely the code. It is the moment a human decides that a message looks trustworthy enough to act on.

For our readers, the practical takeaway is not to abandon digital banking or to treat every request with paranoia. It is to recognize that verification is no longer optional, it is the price of participation in a connected economy. If a government agency or a financial institution contacts you with an urgent request, pause. Call the official number on their website. Do not use the contact details in the message. This simple habit, applied consistently, can blunt the impact of the exact technique that compromised Revolut. The company has not disclosed how many customers were affected, but the fact that they are working with regulators suggests the scope is serious enough to warrant oversight.

What we would tell a reader who asks us about this is straightforward: expect this to happen again, and prepare accordingly. Not because Revolut is uniquely vulnerable, but because the attack method, abusing government requests, is efficient and scalable. The same way we have learned to verify links before clicking, we must learn to verify identities before sharing sensitive information. The open question is whether financial institutions will begin building friction into these verification processes, or whether they will continue to rely on customers to spot the difference between a legitimate request and a convincing fake. Watch for that shift. It will tell you more about the industry's commitment to security than any press release ever could.

From TechCrunch

Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.

Read the original at TechCrunch