LONDON, United Kingdom — Revolut has confirmed that some customer information was exposed after attackers used fraudulent requests impersonating government and law-enforcement authorities to persuade employees to disclose data.
The London-based financial technology company said the incident involved a small proportion of its customer base and resulted from social engineering rather than a compromise of its core banking infrastructure.
The disclosure highlights a growing security risk for financial institutions: attackers can target employees and customer-support processes even when the underlying technology remains secure.
Attackers impersonated authorities
Revolut said the attackers used fraudulent requests designed to appear as legitimate government or law-enforcement demands for customer information.
Such requests can be particularly effective because financial institutions routinely receive legitimate requests from authorities seeking information as part of investigations.
The attackers sought to exploit that process by presenting employees with requests that appeared to have an official basis.
Revolut said the incident was detected and that it took steps to contain the exposure.
The company has not indicated that the incident resulted from unauthorized access to its central banking systems.
Customer information was exposed
The information involved was customer data held by Revolut. The company said the number of affected customers represented only a small percentage of its overall customer base.
The exact information exposed can vary according to the customer and the information available to employees responding to the fraudulent requests.
Revolut has said affected customers were notified and that it strengthened its controls following the incident.
The company has also emphasized that customers should remain alert to subsequent attempts to exploit information obtained during the breach.
Social engineering remains a major security risk
The incident illustrates why cybersecurity risks for financial institutions extend beyond technical attacks such as malware or unauthorized network access.
Social engineering relies on manipulating people and procedures.
An attacker does not necessarily need to break through a bank’s technical defenses if they can persuade an employee that a fraudulent request is legitimate.
Government impersonation can make that tactic particularly convincing because employees handling sensitive information may be accustomed to responding to official requests.
Financial institutions therefore need to verify not only the identity of the person making a request but also whether the request itself is authentic and legally valid.
Revolut strengthens safeguards
Revolut said it responded to the incident by introducing additional safeguards around requests for customer information.
The company has also investigated the circumstances surrounding the exposure and said it was working to prevent similar incidents.
The response reflects the difficulty of securing systems that depend on employees making rapid decisions while handling large volumes of legitimate customer and regulatory requests.
Additional verification can reduce the risk of fraudulent disclosures, but it can also increase the time required to respond to legitimate authorities.
Financial companies therefore face a continuing balance between protecting customer information and meeting lawful information requests.
Customers face a secondary risk
A data exposure does not necessarily result in immediate financial losses for affected customers.
However, information obtained through such an incident can potentially be used in subsequent fraud attempts.
Attackers who know personal or account-related details may be able to make later communications appear more convincing.
Customers should therefore treat unexpected calls, emails or messages claiming to come from Revolut, government agencies or law-enforcement authorities with caution.
Revolut has advised customers to use official channels rather than relying on unsolicited communications when dealing with account-security concerns.
Broader implications for financial institutions
The incident comes as financial institutions face increasingly sophisticated fraud and cyber threats.
Banks and fintech companies hold large amounts of sensitive information while operating complex customer-service and compliance systems.
Those systems create multiple points where an attacker can attempt to manipulate an employee, contractor or automated process.
The Revolut incident demonstrates that protecting customer information requires more than securing databases and networks. Verification procedures surrounding access to information can be equally important.
For Revolut, the immediate priority is limiting the consequences for affected customers and ensuring that the fraudulent-request technique cannot be repeated.
For the wider financial sector, the case provides another reminder that trusted internal processes can themselves become targets for sophisticated social-engineering attacks.
Reporting Credit: Revolut — official incident disclosure, customer-security information and response measures; relevant law-enforcement and government authorities — verification and legal-request procedures where publicly documented.














