Revolut Data Breach Exposes Passport Data of Irish Customers
Fintech giant Revolut has confirmed that a targeted data breach has compromised the sensitive personal information of hundreds of users, including account holders based in Ireland. The security incident, which involved unauthorised third parties gaining access to government-issued identification documents, has prompted immediate regulatory reporting and highlighted the legal avenues available to victims under Irish data privacy law. Revolut revealed that around 680 customers internationally were caught up in the intrusion, with at least 12 confirmed victims located in the Irish jurisdiction.
The breach unfolded after an external threat actor orchestrated an impersonation scheme designed to deceive internal verification staff. By using a legitimate government agency domain, the perpetrators submitted fraudulent information requests that appeared authentic to customer support and compliance personnel. Before the scam was detected and the originating address blocked, files containing sensitive Know Your Customer (KYC) documentation were released. The compromised records include photographic scans of passports and driving licences, alongside dates of birth, residential addresses, email accounts, and telephone numbers.
With a user base exceeding 3.4 million in Ireland, Revolut has become central to the daily financial transactions of a significant portion of the population. Although the proportion of affected Irish users is comparatively small, the nature of the compromised information presents severe security ramifications. Banking identification files of this calibre represent the cornerstone of modern identity verification, making their unauthorised dissemination an urgent issue for both individuals and regulatory authorities.
Elevated Threat of Identity Theft and Secondary Fraud
Data security specialists point out that the exposure of government identity documents carries far greater long-term dangers than typical breaches involving passwords or contact records. Armed with verified passport images, official driving licences, and accurate home addresses, bad actors possess the necessary material to bypass identity verification controls across various digital services. Victims face the immediate hazard of fraudulent bank accounts or credit facilities being established in their names, as well as the diversion of state benefits or tax filings.
Furthermore, affected individuals are placed at heightened risk of secondary social engineering and phishing attacks. Fraudsters frequently utilise accurate, compromised personal details to establish credibility, posing as fraud investigators, telecommunications providers, or financial institutions. Revolut has indicated that it contacted the affected individuals directly to outline the event and supply support channels. Security analysts strongly advise impacted account holders to initiate ongoing credit monitoring, notify identity protection services, and exercise extreme caution when responding to unsolicited communications.
Regulatory Oversight and the Data Protection Commission
The breach has placed Revolut’s security and verification protocols under the lens of the General Data Protection Regulation (GDPR). Under statutory rules, data controllers operating within the European Union must notify the Data Protection Commission (DPC) within 72 hours of becoming aware of a personal data breach that creates a risk to individuals' rights and freedoms. Where the breach presents a high risk to those affected, controllers are legally bound to inform data subjects without undue delay.
Revolut confirmed that upon discovering the intrusion, it notified the relevant government agency, law enforcement bodies, financial supervisory authorities, and data privacy regulators. The DPC possesses robust investigative powers and can scrutinise whether the fintech institution implemented adequate technical and organisational safeguards to prevent such unauthorised disclosures. Financial entities handling extensive volumes of identity documentation are expected to maintain stringent secondary verification measures before fulfilling external data requests, regardless of the apparent authority of the sender.
Legal Remedies and Compensation Under Irish Law
For individuals in Ireland whose identification records have been improperly disclosed, the incident raises vital questions regarding civil liability and financial redress. Under Section 117 of the Data Protection Act 2018, which transposes relevant aspects of the GDPR into domestic legislation, individuals whose data rights have been infringed are entitled to initiate legal proceedings against data controllers. These actions may be brought before the Circuit Court or the High Court to recover damages for both material losses and non-material harm, including emotional distress, anxiety, and psychological upset.
The landscape of Irish data claims has evolved substantially following recent decisions from both the Irish courts and the Court of Justice of the European Union (CJEU). While the judiciary has affirmed that compensable non-material damage can encompass the genuine distress and anxiety caused by the exposure of sensitive identification papers, claimants must demonstrate actual damage rather than relying simply on the occurrence of the breach itself. Where identity theft poses an ongoing threat, establishing that tangible distress has resulted from the loss of control over one's identity documents remains central to pursuing a viable civil remedy.
Free Claim Assessment
Find out if you have a valid claim — free, no obligation.
Start Free Assessment