Revolut Data Breach: Irish Customers Warned Over Passport And ID Document Risk
Revolut users can check if they were caught in the data breach by messaging the in-app chat. Revolut says it contacted affected customers directly.
Revolut has confirmed that sensitive customer information, including copies of passports and driving licences, was released to an unauthorised third party after the company received fraudulent requests sent from a legitimate government agency email domain. Cybersecurity firm ESET Ireland has warned Irish account holders to be alert for follow-up scam calls, saying that leaked identity documents cannot simply be reset the way a password can.
The incident was not a hack in the conventional sense. According to Revolut, the requests for the data arrived from a genuine government agency email domain and were treated as genuine.
A Revolut spokesperson:
"Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."
A Revolut spokesperson:
"Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators."
The company said its systems and customer funds are unaffected, and that it has contacted the limited number of impacted individuals directly to inform them and provide support.
According to a notification emailed to affected customers and reviewed by TechCrunch, the exposed data included identity and contact details such as dates of birth, postal and email addresses and phone numbers, along with copies of identity documents including passports and driving licences. Verification selfies, account statements and transaction histories were also listed.
Revolut has not disclosed how many people were affected, whether the incident was limited to a particular market, or which government agency's domain was used.
Revolut had 3.4 million customers in Ireland at the last count in June, according to its own figure. That scale is why ESET Ireland is urging caution even among customers who have received no notification.
Customers who want to check their own position can ask Revolut directly inside the app. Open Revolut, tap your profile image, then open Chats and send a message to support asking whether your personal data was affected in the data breach disclosed over the last 24 hours. Replies have been arriving within moments, and where an account was not involved the assistant confirms that the account was not impacted, that funds, credentials and personal details remain secure, and that no action is needed.
That reply comes from Revolut's automated chat assistant rather than from a named member of staff. Anyone who wants a formal, documented answer can instead make a subject access request under Article 15 of the General Data Protection Regulation, which obliges the company to confirm what personal data it holds about them and how it has been used.
It is worth stressing that this check should only ever be started from inside the Revolut app itself. Do not use a phone number, link or QR code sent to you by text, email or social media, however convincing it looks.
The concern is not the leak itself, but what the material can be used for. A password can be reset in a minute; a passport scan cannot. A caller holding someone's date of birth, address, mobile number and photo ID can sound entirely legitimate, because every detail they quote is correct.
George Foley, Cybersecurity Specialist, ESET Ireland: "The call will come from someone claiming to be Revolut's fraud team, and they will know things about you that only your bank should know."
George Foley:
"That is how they get past your guard. Then comes the bit that costs you money. Your account has been compromised, they say, so move your balance to this safe account while we sort it out. There is no safe account."
George Foley:
"Revolut will not ring you and ask you to move money, and neither will AIB, Bank of Ireland or the Gardaí. If you get that call, hang up, open the app and message them yourself."
ESET Ireland has also warned that stolen documents could be used to open accounts or apply for credit in other people's names, which may not come to light for months. Anyone who received a notification from Revolut is advised to check their credit record with the Central Credit Register, which is free, and to consider replacing the affected document if Revolut confirms an ID copy was included.
There is a second warning here for businesses. Firms that hand over personal data to Revenue, the Gardaí, the HSE or a local authority on request should consider how they would establish that such a request was genuine.
George Foley:
"Whoever did this worked out that they did not need to break in. They got hold of a real government email account and asked politely, and a compliance team somewhere did its job and answered."
George Foley:
"A genuine sender address is not the same as a genuine request. If someone asks you for sensitive data by email, ring them back on a number you already have, not the one at the bottom of the message. It is a five minute call. Revolut is now finding out what it costs to skip it."
Separately, people claiming responsibility for obtaining the data have posted in Telegram groups, stating that they intend to release further material unless Revolut pays them. These claims have not been independently verified.
This is not the first such incident at the company. In September 2022, Revolut disclosed a breach in which attackers obtained the personal, contact and financial information of 50,150 customers, an incident that was investigated by Lithuania's State Data Protection Inspectorate, where Revolut holds its banking licence.
Anyone who believes they have been targeted by a scam call or message should contact their bank directly through its official app and report the matter to their local Garda station.