Revolut Confirmed Data Incident Affecting About 680 Customers Across Europe
Revolut sign at their Canary Wharf offices, London. brunocoelho / Shutterstock.com.

Revolut confirmed that attackers used fraudulent information requests to obtain data relating to about 680 customers. The requests were sent through a compromised Italian government email system, according to reports by the Financial Times and the Guardian. Revolut said its internal systems were not breached and customer funds remained secure. The company contacted affected individuals and notified relevant authorities and regulators.

The Financial Times reported that the scheme operated over several months and primarily targeted customers believed to hold cryptocurrency. It said most affected customers were in Switzerland and France, with others across 31 European countries. The Guardian reported an alleged $3 million ransom demand. Revolut said it had received no direct demand from the alleged group.

FRAUDULENT REQUESTS USED GOVERNMENT EMAIL

Revolut said the attackers had compromised an Italian government email system and used a legitimate agency domain to make requests that appeared official. The company blocked the address after identifying the fraud and alerted the relevant agency, law-enforcement bodies and data-protection and financial regulators. No evidence reviewed indicated that the attackers entered Revolut’s core systems.

The incident shows how authenticated external channels can be abused even when a financial institution’s own technology remains intact. Customer information can create personal-security and fraud risks once released to an impostor. Revolut’s response therefore centres on the information disclosed and the affected individuals, rather than on losses from its accounts.

SCOPE AND REGULATORY FOLLOW-UP

The reported total represents a small share of Revolut’s roughly 80 million customers, but the cases span numerous European jurisdictions. The company said it blocked the address used in the scheme. Public notices from the Irish or Italian data-protection authorities were not located in the sources reviewed.

The next milestone is any public finding by the relevant data-protection or financial regulators on the requests and Revolut’s controls. Until then, the confirmed facts are limited to the fraudulent requests, the affected customer group and the company’s response. Claims about the alleged ransom or wider access should remain attributed to reporting rather than treated as regulatory findings.