Revolut Hit by Sophisticated Impersonation Scam Exposing Customer Data
Digital banking giant Revolut has fallen victim to a sophisticated social engineering scam that exposed sensitive customer data. The breach occurred when attackers impersonated a government agency, using a legitimate email address and domain credentials to trick Revolut's compliance systems into handing over data. This included full names, dates of birth, postal addresses, email addresses, phone numbers, occupations, passports or driver's licenses, verification selfies, and financial histories.
The attack targeted high-net-worth individuals and crypto-focused accounts, exposing sensitive information on over 80 million customers worldwide. The hackers also obtained IBANs, account statements, withdrawal records, and complete transaction histories detailing Bitcoin activity. Following the incident, a hacker group called 'Revolut Smilik' began circulating stolen data on Telegram, attempting to extort the company.
Security experts note that this incident highlights a critical vulnerability in institutional trust architectures: even when core software security is strong, human-centric social engineering can exploit verified communication channels for targeted data theft. Revolut has maintained that its internal databases and customer funds remain safe, but agencies such as the UK's Financial Conduct Authority (FCA) and Information Commissioner's Office (ICO) have opened inquiries to evaluate the breach.