Wire Observer.
Technology

Revolut Says Hackers Accessed Passport Scans and Full Transaction Records After Fake Government Request

Revolut Says Hackers Accessed Passport Scans and Full Transaction Records After Fake Government Request

Revolut, the London‑based financial‑technology firm, has confirmed that a cyber incident exposed customers' passport images and complete transaction histories after the company acted on a fraudulent request that mimicked a legitimate government agency.

According to the company's statement, the deceptive request appeared to come from an official source, prompting internal teams to provide the requested data. Subsequent investigation revealed that the information was intercepted by unauthorized actors, granting them access to highly sensitive personal documents and a full ledger of users' financial activity.

Revolut, which serves millions of users across Europe and beyond, has long positioned itself as a secure alternative to traditional banking. Nonetheless, the breach highlights the persistent challenge fintech firms face in safeguarding data against increasingly sophisticated social‑engineering attacks. While the firm has not disclosed the exact number of affected accounts, it emphasized that the compromised material includes passport copies and a detailed record of transactions.

In response, Revolut has launched an internal forensic review, engaged external cybersecurity experts, and reported the incident to relevant data‑protection authorities. The company is also notifying affected customers, urging them to monitor their accounts for unusual activity and to consider changing authentication credentials where appropriate. Additional security measures, such as stricter verification of external data requests, are being rolled out to prevent a recurrence.

The episode arrives amid a broader wave of cyber threats targeting financial services worldwide, prompting regulators to scrutinize compliance with data‑privacy standards such as the EU's GDPR. Analysts suggest that the incident could trigger further regulatory oversight and potential penalties if systemic weaknesses are identified. For users, the breach serves as a reminder to remain vigilant, regularly review account statements, and stay informed about the security practices of the platforms they trust.

Diya Sharma — AI & research desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related