Revolut says security is "at the heart of everything we do." In 2018, they turned off the system that screens for money laundering and sanctions violations. For three months -- July, August, September -- thousands of transactions flowed through with no automated checks. A whistleblower had to contact the board to flag it. The CFO, a 12-year JP Morgan veteran, quit shortly after. Revolut's explanation: they were "trialing" a new system and the old one was "running in parallel." The whistleblower said otherwise. Seven years later, Lithuania hit Revolut with its largest-ever AML fine for still failing to monitor transactions properly. Revolut grew from zero to 45 million users. Its compliance systems didn't keep up. Lithuania's central bank hit Revolut with its largest-ever AML penalty -- EUR 3.5 million -- for failing to identify suspicious transactions. The monitoring systems couldn't track customer activity in real time. They weren't standardized across markets. Australia fined Revolut separately for late compliance reports. The company spent eight years trying to get a UK banking license because regulators kept flagging compliance failures. Revolut moved fast. Compliance moved slow. The customers in between were unprotected.
What they claim: Revolut's privacy settings include options to opt out of social media and advertising data sharing, implying that opting out actually stops data from being shared.
What we found: Independent research found that the Revolut app shares sensitive user data with Facebook through the Facebook SDK, including: IP address, device name, network carrier name, timezone, and a unique tracking identifier. This data is transmitted regardless of whether the user has a Facebook account. A researcher who specifically opted out of social media and advertising in Revolut's privacy settings confirmed that data was still being sent to Facebook. The opt-out toggle exists in the app but does not stop the data flow. Revolut received a 0/10 privacy score on privacy-focused platforms due to extensive Google and Facebook trackers embedded in the app.
What they claim: Revolut positions CEO Nik Storonsky as a visionary fintech leader who left traditional banking to build a better financial system for consumers.
What we found: Nik Storonsky was born in Dolgoprudny, Russia, 20km north of Moscow. He worked at Lehman Brothers from 2006 to 2008, trading over $2 billion in equity derivatives -- until Lehman collapsed in the largest bankruptcy in US history. He then moved to Credit Suisse from 2008 to 2013 -- which was later absorbed by UBS in 2023 after its own collapse. He founded Revolut in December 2013 with GBP 300,000 of savings. Wired documented a toxic workplace culture under Storonsky: 80% of employees lasted less than a year, over 50% less than six months. Storonsky expressed surprise that senior staff weren't working weekends and affirmed that underperformers would be "fired without negotiations." His net worth reached $18.8 billion on the Forbes 2026 list while customer accounts were being frozen for weeks.
What they claim: Revolut states it collects personal data that is "necessary for the performance of our contract with you" and "to comply with legal obligations."
What we found: The Revolut app contains extensive Google and Facebook trackers and requests permissions including: audio recording, camera access, precise location, and contacts. The app received a 0/10 privacy score on privacy-focused evaluation platforms. Revolut's privacy policy discloses sharing personal data with credit reference agencies, payment recipients, government agencies, and unnamed "companies that help us provide products." The app creates behavioral profiles based on how customers use the service. For a banking app that holds customer savings, salary deposits, and complete transaction histories, the surveillance footprint resembles a social media platform more than a financial institution.
What they claim: Revolut states it processes personal data in accordance with GDPR and gives users "control over their personal information."
What we found: Revolut rolled out new data practices that automatically opted every customer in to sharing data for marketing purposes and with credit bureaus. There was no opt-in mechanism -- customers had to discover the change and manually opt out. The data sent to credit bureaus was used to develop Revolut's own lending products by analyzing what it thought customers could afford. The Irish Data Protection Commission contacted Revolut "as a matter of urgency" over GDPR compliance concerns. The company effectively used its customers' financial data to build a lending business, enrolling them without consent in a data-sharing arrangement that primarily benefited Revolut.
What they claim: Revolut states it maintains "robust systems and controls" to detect and prevent money laundering and financial crime, and that "security is at the heart of everything we do."
What we found: The Daily Telegraph reported in February 2019, citing internal documents, that Revolut switched off an automated sanctions screening system designed to stop suspicious transactions for three months in 2018 (July-September). Thousands of potentially illegal transactions may have passed through unchecked. A whistleblower contacted Revolut's board in late 2018 over the sanctions screening failures. CFO Peter O'Higgins, who had spent 12 years at JP Morgan, quit at the start of 2019. Revolut claimed its original system was "running in parallel" -- but the whistleblower disputed this. The Bank of Lithuania later fined Revolut EUR 3.5 million in April 2025 for ongoing AML monitoring failures.
What they claim: Revolut promotes itself as a "trusted" alternative to traditional banks, emphasizing its rapid growth and banking licenses as evidence of regulatory approval.
What we found: In April 2025, Lithuania's central bank fined Revolut EUR 3.5 million -- Lithuania's largest-ever AML penalty. The Bank of Lithuania determined that Revolut "did not always properly identify suspicious monetary operations or transactions." Transaction monitoring systems failed to track customer activity in real time. The regulator found that Revolut's explosive growth -- from startup to 45 million users -- outpaced its compliance infrastructure. Monitoring systems became overwhelmed. Procedures weren't standardized across markets. Separately, Australia's AUSTRAC fined Revolut AU$187,800 for late compliance report submissions. The company had used its Lithuanian banking license to serve all of Europe while its UK license was delayed for eight years due to compliance concerns.
What they claim: Revolut markets itself as giving customers "complete control" over their money with "instant" access and "24/7 support."
What we found: Hundreds of Revolut customers have reported accounts frozen for weeks with no explanation and no accessible support channel. The Times reported a case where two accounts totaling EUR 300,000 were blocked for six full weeks without the customer being given a reason. Social media platforms are filled with users unable to access their funds, describing automated responses and no human support. Which? consumer group investigated and found the pattern was systemic, not isolated. Customers who deposited their salaries, savings, or business income into Revolut found themselves locked out of their own money with no timeline for resolution and no way to reach a human being.