Revolut has confirmed that a scam involving emails led to a data leak affecting some of its customers. The key detail: the attackers sent messages from a real government domain, so recipients saw an address they were used to trusting. This is classic phishing with a trusted sender, and it is dangerous precisely because it breaks the usual 'check the sender' habit.

What happened

According to the company, a third party used a legitimate government email domain to send the messages. As a result, confidential information from a 'limited number' of customers was exposed. Revolut is a British fintech known for multi-currency accounts and virtual cards, so the incident directly concerns anyone who pays for overseas services with such cards.

Why it matters for virtual card holders

A virtual card is, at its core, credentials: the number, expiry date, CVV, and sometimes the cardholder's details. If scammers obtained some of this data, the main risk is not that the card was 'hijacked' outright, but that the data could be used for targeted phishing: emails 'from the bank', 'from a government agency', or 'from a service' asking you to confirm a limit, update 3DS, or reissue your card.

  • Limits. Even after a leak, the damage is limited if the card has a sensible daily/monthly limit and only the required amount is stored on it.
  • 3DS. Confirming a payment with a code from an app or SMS is the main barrier to unauthorised charges. If a service asks you to 'disable 3DS for convenience', that's a red flag.
  • Regions. Many virtual cards let you restrict the geography of transactions. If you only pay for US/EU services, you can turn off other regions.
  • Typical declines. After leaks, banks often tighten anti-fraud: payments may be declined on suspicion of fraud. It's not always a 'service problem' — sometimes it's protection kicking in.

What to do in practice

Check whether you've received emails from government agencies or 'Revolut' asking you to click a link and enter your details. Never enter card credentials or 3DS codes via a link in an email — open the app or website manually. If in doubt, issue a new virtual card: it's faster and cheaper than sorting out disputed charges.

The rule is simple: a trusted sender domain is no longer a guarantee. Check not the address, but the action you're being asked to take.

Takeaway

The Revolut incident is a reminder that phishing is evolving from 'bad addresses' to using real domains. For those who pay with virtual cards for overseas subscriptions and services, the best protection is limits, enabled 3DS, regional restrictions, and the habit of never entering data via links in emails.

This material is for information only and is not financial advice.

VirtCardPay

A virtual card in 2 minutes

Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.

Open in Telegram Learn more about the service →

Sources

This material is for informational purposes only and is not financial advice. Data and service terms may change, so check primary sources before making a payment or investment decision. Mentions of third-party brands and services do not imply official partnership, support, or endorsement by VirtCardPay.
Back