Revolut Data Breach Exposes Irish Customers After Scam Requests
- A data leak at Revolut has exposed sensitive personal information, including passport copies and bank data, after fraudsters submitted fraudulent requests using a legitimate government agency email domain,...
- The fintech company has confirmed that approximately 680 customers worldwide were affected by the breach, with 12 of those impacted based in Ireland, according to RTÉ.
- According to coverage by the Irish Times, the incident involved copies of passports and driving licences being handed over to criminals, alongside dates of birth, home addresses, email...
A data leak at Revolut has exposed sensitive personal information, including passport copies and bank data, after fraudsters submitted fraudulent requests using a legitimate government agency email domain, according to reports from outlets including the Irish Independent and RTÉ.
The fintech company has confirmed that approximately 680 customers worldwide were affected by the breach, with 12 of those impacted based in Ireland, according to RTÉ. Revolut operates with a large footprint in the country, boasting around 3.4 million customers in the Irish market. Affected individuals have been contacted directly by the company, as reported by RTÉ.
Stolen Passports, IBANs and Contact Data Exposed
According to coverage by the Irish Times, the incident involved copies of passports and driving licences being handed over to criminals, alongside dates of birth, home addresses, email addresses, and phone numbers.
TechCrunch initially reported the exposure, noting that International Bank Account Numbers (IBANs) and other identity and contact details were also potentially accessed.
How Fraudsters Weaponised Official Government Email Domains
Revolut described the incident as a sophisticated external impersonation scam rather than a cyberattack on its core infrastructure.

According to a company statement cited by RTÉ, an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.
Because financial institutions are legally required to respond to official requests from law enforcement and government bodies, Revolut processed the demands through its normal compliance procedures.
Immediate Lockdown and Regulatory Notifications Triggered
Once the fraudulent activity was detected, Revolut stated that it immediately blocked the offending email address, according to RTÉ. The company also alerted the relevant government agency, law enforcement authorities, data protection officials, and financial regulators.
High-Stakes Expansion Continues Amid Global Growth Goals
The fintech has also been weighing a potential stock market listing, alongside a significant investment commitment in the United States and conditional approval to operate as a national bank there.
