Revolut experiences embarrasing data breach, Irish impact unknown

sponsored by

I will always sing the praises of Revolut for how they pressure traditional banks into innovation. However the world of finance and the world of “move fast and break things” probably shouldn’t meet so often. Revolut has been left with egg on its face after a very serious data breach, resulting in personal data of customers being handed over to bad actors. What’s worse is that, simply put, Revolut was asked for the data and they just obliged. Seems a little too easy, eh?

What is the Revolut data breach?

This week, Revolut confirmed it had disclosed sensitive customer data to an unauthorised third party after receiving a fraudulent information request that arrived from a genuine government agency’s email domain, carrying the authentication credentials that would normally mark it out as legitimate. The popular neo-bank has described the events as a “a sophisticated external impersonation scam” in which someone gained control of an email account operating inside a real government agency’s domain and used it to file bogus requests requests for information.

The request passed the checks Revolut normally relies on to establish that a government or law enforcement enquiry is genuine. The company hasn’t said which agency was impersonated, which country was involved, or how many customers were caught up in it.

What data is involved in the Revolut breach?

The notification sent to affected customers, and corroborated by CyberInsider’s own reporting, breaks the exposure into four categories.

Kindly sponsored by
  • Identity details
    • Full name
    • Date of birth
    • Occupation.
  • Contact details
    • Postal address
    • Email address
    • Phone number.
  • Document and verification data
    • Including a copy of a passport or driving licence
    • Verification selfie taken at sign up
  • Financial data
    • IBANs
    • Account status
    • Opening date
    • Wallet reference number
    • Withdrawal records
    • Complete transaction history
    • Bitcoin activity.

Revolut says no biometric facial telemetry data was involved, but still, this is a treasure trove of personal data to hand over to bad actors.

Because the financial data handed over included full transaction histories, on chain activity is part of what’s exposed for some customers. Blockchain investigator ZachXBT, who first brought the notification to public attention, said the incident appeared to target customers with visible crypto wealth, as reported by Decrypt. The concern isn’t abstract. Once someone’s real name and address are linked to a public wallet, the risk shifts from online fraud to something that can turn up at your front door.

Brought to you by

Does this touch Revolut’s Irish customers?

Revolut has around 3.4 million customers in Ireland, a figure that puts it in daily use across most of the country. The company hasn’t confirmed which markets were affected by this breach. I have reached out to Revolut directly whether any Irish customers were among those included, and as of publishing this, there’s been no response. I’ll update this piece the moment that changes.

There is speculation online that the request Revolut received may have targeted only accounts with high net worth, so for once my crap bank balance might pay off for me here.

Kindly sponsored by

What Revolut has done to mitigate risk for customers?

Once the fraud was identified, Revolut blocked the email address, alerted the government agency whose domain had been used, and notified law enforcement, data protection authorities and financial regulators. It says it has contacted affected customers directly and put precautionary protections in place for them.

There are two reliable ways to find out if you’re affected, and everything else is guesswork. The first is the direct notification Revolut sends to anyone it believes was included. The second is a formal subject access request under GDPR Article 15, which any Irish customer can lodge to see exactly what data Revolut holds and has shared, following the Data Protection Commission’s guidance on subject access requests.

Not getting a notification doesn’t mean you’re in the clear. It just means nothing has landed in your inbox yet.

Brought to you by

Written by

Marty
Martyhttps://muckrack.com/marty-goosed
Founding Editor of Goosed, Marty is a massive fan of tech making life easier. You'll often find him testing something new, brewing beer or finding some new foodie spots in Dublin, Ireland. - Find me on Bluesky

Sponsored by

Related articles

Brought to you by

Get more Goosed

Discussion

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.