Business / news

Revolut Confirms Customer Data Breach Tied to Spoofed Government Requests

British fintech Revolut has confirmed that sensitive customer information was handed to an unauthorized third party after fraudulent requests arrived from a legitimate government agency email domain.

The company said the impersonation scam was sophisticated, with the outside party using a genuine government domain to file the bogus information requests. Revolut described the incident as an external impersonation scam rather than a breach of its own systems.

Data exposed in the episode included customers' identity and contact details — birth dates, postal and email addresses, and phone numbers — along with copies of identity documents such as passports and driver's licenses, according to a notification sent to affected customers. The notification also said verification selfies, account statements, and transaction histories may have been included.

A Revolut spokesperson said a "limited" number of customers were affected and that the firm had contacted them directly. The company did not say how many individuals were impacted, declined to identify the government agency involved, and did not answer whether the incident was confined to a single market.

Revolut said it notified the affected customers and alerted the relevant government agency, law enforcement, and financial regulators. The fintech, one of Britain's most valuable private companies, has not publicly detailed any additional steps taken since the disclosure.