Revolut confirms data breach via fake government agency emails

Revolut confirms data breach via fake government agency emails

Revolut has confirmed a data breach after fraudsters used a legitimate government agency email domain to send it fake requests for customer information. In a notification emailed to affected customers and reviewed by TechCrunch, the London based fintech said the exposed data included customers' identity and contact details such as birth dates, postal and email addresses, and phone numbers, plus copies of identity documents including passports and driver's licenses. Revolut said the exposure may have also included verification selfies, account statements, and transaction histories.

A Revolut spokesperson told TechCrunch that a "limited" number of customers were affected and that the company had contacted them directly, but Revolut did not disclose the exact number, whether the incident was confined to a specific market, or which government agency's domain was impersonated. The spokesperson said Revolut had "identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," adding that the company blocked the email address once it discovered the scam and alerted the government agency, law enforcement, and relevant regulators. Revolut said its systems and customer funds are unaffected.

Crypto security researcher ZachXBT posted about Revolut's notification email to affected customers late on Friday, saying the incident appeared to have targeted high net worth users.

The breach lands as Revolut, which has more than 80 million customers globally and operates as a bank in more than 30 countries, is expanding its footprint: it has recently pushed into markets including India, Mexico, France and the UAE, secured banking licenses in France and the UK, and this month received conditional approval from the U.S. Office of the Comptroller of the Currency to set up a national bank, which it expects to launch in the first half of 2027. Revolut is also reportedly weighing a public listing that could value it at as much as $200 billion, up from a $75 billion private valuation in November.

Key facts

  • Revolut confirmed it disclosed sensitive customer data to an unauthorized third party after fraudsters sent requests from a legitimate government agency's email domain.
  • Exposed data included birth dates, addresses, phone numbers, and copies of passports and driver's licenses; verification selfies, account statements, and transaction histories may also have been exposed.
  • Revolut said a "limited" number of customers were affected and contacted directly, but declined to give an exact count, name the market involved, or identify the impersonated agency.
  • Crypto researcher ZachXBT said the incident appeared to target high net worth users.
  • The breach comes as Revolut, with more than 80 million customers in over 30 countries, pursues U.S. banking approval and reportedly weighs a public listing that could value it at up to $200 billion.

Why it matters

This is not a hack of Revolut's own systems: attackers spoofed a real government agency's email domain to trick the fintech into handing over customer records directly, a social engineering route that bypasses technical defenses entirely. It hit a company with more than 80 million customers just as Revolut pushes into new markets, seeks a U.S. banking license, and reportedly courts a public listing valued as high as $200 billion, raising the stakes on how it handles the disclosure.

Who it affects

Revolut described the affected group only as a "limited" number of customers who have been contacted directly. Revolut did not say which country or market was involved. ZachXBT, who first flagged the customer notification, said the incident appeared to have been aimed at high net worth users specifically.

How to use it

Customers who receive a breach notification from Revolut should treat it as confirmation that identity documents, not just contact details, may be in unauthorized hands, and take the usual steps: watch for phishing that references the leaked details, and monitor accounts for fraudulent use of the exposed identity documents. For anyone handling data requests that claim to come from a government agency, the underlying lesson is to verify the request through an independent channel rather than trusting the sender domain alone.

How solid is it

The account rests on Revolut's own notification to affected customers, reviewed directly by TechCrunch, plus on record quotes from a Revolut spokesperson confirming the scam and the company's response. ZachXBT's post corroborates that the notification went out and adds the targeting detail, but is a secondary account of the same email rather than an independent source.

Risks and caveats

Revolut has not disclosed the number of customers affected, the market involved, or the identity of the impersonated government agency, and the article does not state whether any of the exposed data, including the identity documents and possible selfies, has since been misused. Revolut says its systems and customer funds were not affected, but that claim covers infrastructure, not the data that was already handed over before the scam was caught.

“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information”

— Revolut spokesperson, to TechCrunch