Revolut has confirmed that sensitive information belonging to a limited number of customers was disclosed to an unauthorized third party after attackers impersonated a government agency. The financial technology company said its systems were not compromised and that customer funds were unaffected.
The attackers allegedly used a legitimate email domain belonging to a government agency to send fraudulent requests. Revolut said it blocked the address after detecting the fraud and notified the agency, law-enforcement bodies, data-protection organizations and financial regulators.
The data exposed may include the following information, depending on the customer involved:
- Names and dates of birth
- Postal addresses and email addresses
- Phone numbers
- Copies of identity documents, including passports or driving licenses
- Selfies used for identity verification
- Bank statements
- Transaction histories
Revolut has not disclosed how many customers were affected or whether the incident was confined to a particular country. It said it had contacted affected users directly.
Security researcher ZachXBT has suggested that high-net-worth customers may have been a particular target, though Revolut has not confirmed that assessment. Customers who receive a notification should be alert to follow-up phishing attempts, fraudulent calls and messages seeking passwords, authentication codes or money transfers, as the exposed personal details could make such scams more convincing.
The disclosure comes as the London-based company continues its international expansion and considers a possible public listing at a valuation of up to $200 billion. Revolut says it serves more than 80 million customers worldwide; the number and geographic scope of those affected by this incident remain unconfirmed.







