Revolut has confirmed a user data breach after a scammer gained access to sensitive info by using an email address spoofed to look like it came from a government agency. Exposed data includes passport scans, selfie shots used for identity checks, and transaction histories for some customers.
What happened
According to the company, the attacker used a fake 'government' email to get into customer records. The compromised information covers document images, user photos, and details of certain clients' financial transactions.
Why it matters
When scammers get both passport data and selfies, it opens the door to identity theft and account takeovers. Having access to transaction histories also lets them target users more precisely and try to squeeze out even more info. For fintech apps, this attack vector is one of the most dangerous—it undermines KYC checks and erodes user trust.
How to protect yourself
Double-check the domains and headers of incoming emails, never send documents in response to random email requests, and stick to official chat channels in the app or on the website. Turn on two-factor authentication, update your passwords, and keep an eye on login and transaction alerts. If anything feels off, freeze your cards and contact support through the official channel right away.
