Revolut Discloses Customer Data Breach After Falling for Fraudulent Government Requests
The British fintech fell victim to a sophisticated impersonation scheme in which attackers used a legitimate government email domain to trick the company into handing over sensitive customer information.

Revolut, a British fintech firm, has acknowledged that it released confidential customer information to an unauthorized party following deceptive requests that appeared to come from a legitimate government agency email address.
The compromised information encompassed personal identifiers and communication details belonging to customers, such as dates of birth, mailing addresses, email addresses, and phone numbers. Additionally, scans of identity documents—passports and driver's licenses—were exposed, according to a message sent to impacted customers and obtained by TechCrunch. The breach may have extended to include selfies taken during verification procedures, financial statements, and records of past transactions, according to the company's communication.
A representative from Revolut stated that the impact affected a limited group of customers and that the organization had reached out to them individually. The company refrained from revealing the precise number of affected parties. The representative also avoided clarifying whether the incident was confined to a particular geographic region and would not identify which government agency's domain was misused.
Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information
Revolut spokesperson
Following discovery of the scheme, Revolut deactivated the fraudulent email account and notified the appropriate government agency, law enforcement authorities, and regulatory bodies. The company emphasized that Revolut systems and customer funds are unaffected.
Revolut operates with a customer base exceeding 80 million individuals across more than 30 countries where it holds banking status, according to company information. The fintech has recently broadened its operations into India, Mexico, France, and the United Arab Emirates. In addition, the U.S. Office of the Comptroller of the Currency granted conditional approval this month for Revolut to establish a national bank, with the company planning to launch this venture during the first half of 2027.
Crypto security expert ZachXBT brought attention to Revolut's customer notification late Friday, noting that the breach appeared to have specifically targeted individuals with substantial wealth.
The breach emerges during a period when Revolut is reportedly considering a potential initial public offering that could assign the company a valuation as high as $200 billion, compared to its $75 billion valuation from November when it was privately held. The company has simultaneously been strengthening its banking operations throughout Europe and internationally, having recently obtained banking licenses in France and the United Kingdom.


