British fintech Revolut has confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The Revolut customer data breach was revealed in a notification emailed to affected customers and reviewed by TechCrunch.
According to the notification, the exposed data included customers’ identity and contact details. This covered birth dates, postal and email addresses, and phone numbers. Copies of identity documents, including passports and driver’s licenses, were also exposed. The data may have additionally included verification selfies, account statements, and transaction histories.
A Revolut spokesperson confirmed that a “limited” number of customers were impacted and said the company had contacted those customers directly. However, Revolut did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
How the Impersonation Scam Worked
The Revolut customer data breach stemmed from what the company described as a sophisticated external impersonation scam. An unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information. This allowed the attacker to bypass initial verification checks that would normally flag suspicious requests.
The spokesperson stated: “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.”
Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party. The company also alerted the relevant government agency, law enforcement, and relevant regulators. In its statement, Revolut added: “Revolut systems and customer funds are unaffected.”
Scope of the Revolut Customer Data Breach
The full scope of the Revolut customer data breach remains unclear. While Revolut confirmed the incident involved a “limited” number of customers, the company has not provided specific figures. It is also unknown whether the breach affected customers in a single country or across multiple markets.
The types of data potentially exposed in the Revolut customer data breach include:
Identity and contact details: birth date, postal address, email address, and phone number
Identity documents: copies of passports and driver’s licenses
Additional data that may have been exposed: verification selfies, account statements, and transaction histories
This combination of information could be valuable to malicious actors. Identity documents and selfies are often used for identity verification, while account statements and transaction histories can reveal financial behavior and account balances.
Well-known crypto security researcher ZachXBT posted about Revolut’s email to its affected customers late on Friday. The researcher said the incident appeared to have been targeted at high net worth users. This suggests the attacker may have been selective in the fraudulent requests submitted to Revolut.
Revolut’s Response and Notifications
Revolut has stated that it contacted affected customers directly. The company’s spokesperson confirmed the limited scope of the incident and noted that systems and customer funds were unaffected. Revolut also took steps to block the email address used in the scam and notified government and law enforcement authorities.
For customers who received a notification, Revolut’s message explained what data was exposed and the nature of the incident. Affected individuals may want to monitor their accounts and communications for signs of suspicious activity. However, the company has not publicly advised specific protective measures beyond direct notifications to those impacted.
Revolut has not answered follow-up questions about whether the incident was limited to a specific market. It also declined to disclose which government agency was involved in the impersonation. This leaves some uncertainty about the full context of the Revolut customer data breach.
About Revolut: Global Reach and Recent Growth
London-based Revolut has more than 80 million customers globally. It operates as a bank in more than 30 countries, according to its website. The fintech recently expanded its presence in markets including India, Mexico, France, and the UAE.
Earlier this month, the U.S. Office of the Comptroller of the Currency granted conditional approval to Revolut to set up a national bank in the country. The firm expects to launch that bank in the first half of 2027. This expansion comes as Revolut has also been securing banking licenses in France and the UK in recent months.
The incident comes as Revolut reportedly weighs a potential public listing. Such a listing could value the company at as much as $200 billion, up from its $75 billion private valuation in November. The Revolut customer data breach may raise questions for the company as it continues to grow and pursue new opportunities.
What Customers Should Know
For customers concerned about the Revolut customer data breach, the company has stated that systems and customer funds are unaffected. Those who received a notification from Revolut have been informed about the specific data that was exposed. Affected individuals may wish to review their account activity and remain alert to potential phishing attempts or suspicious communications.
The incident highlights the risks associated with impersonation scams targeting financial institutions. Even legitimate government agency email domains can be exploited by attackers to submit fraudulent requests. Revolut’s decision to block the email address and alert authorities reflects the steps companies can take once such a scam is discovered.
Revolut has not disclosed the exact number of impacted individuals or whether the incident was limited to a specific market. The company declined to disclose the government agency involved. As a result, some details about the full scope and impact of the Revolut customer data breach remain undisclosed.
Revolut has confirmed a customer data breach after fraudulent requests were sent from a legitimate government agency email domain. The exposed data included identity and contact details, identity documents, and potentially verification selfies, account statements, and transaction histories. A “limited” number of customers were impacted, and Revolut has contacted those customers directly. The company blocked the email address, alerted authorities, and stated that systems and customer funds are unaffected. The incident comes as Revolut continues its global expansion and reportedly weighs a potential public listing.