Revolut reports data breach affecting small number of customers
Revolut has confirmed a data breach resulting from a sophisticated phishing attack, where fraudulent requests were funneled through a compromised government agency email domain. While the fintech company serves approximately 450,000 customers in Cyprus, officials have indicated that only about 680 individuals globally were impacted by the incident. Reports suggest that compromised data may include names, contact details, dates of birth, and potentially identity documents such as passports, driving licenses, and bank statements.
The company has explicitly stated that its internal systems and customer funds remain secure. Following the incident, Revolut notified the Office of the Commissioner for Personal Data Protection in Cyprus, led by Maria Christofidou. The regulatory authority is currently assessing the breach to ensure compliance with data protection laws. Additionally, the company has directly contacted all affected individuals, providing them with necessary guidance on security measures and the steps they should take to protect their accounts.
Cybercriminals have reportedly attempted to ransom the stolen information, threatening further leaks if their demands are not met. While the regulatory assessment in Cyprus is ongoing, authorities, including the Commissioner of Communications and the Cyprus Securities and Exchange Commission, are monitoring the situation to determine if any local customers were among those targeted.