Fintech giant Revolut has confirmed a significant data security incident, admitting to the disclosure of sensitive customer information to an unauthorized third party. The breach occurred when malicious actors successfully executed a sophisticated social engineering attack, posing as a legitimate government agency and submitting fraudulent information requests via an email domain that appeared to be authentic. This incident, which has sent ripples of concern through Revolut’s extensive customer base, highlights the evolving and increasingly cunning tactics employed by cybercriminals to compromise financial institutions and their users.
The compromised data, as detailed in a notification sent to affected customers and reviewed by TechCrunch, encompasses a range of personally identifiable information (PII). This includes critical identity and contact details such as customers’ birth dates, postal addresses, email addresses, and phone numbers. More alarmingly, the breach also involved the exposure of copies of identity documents, including passports and driver’s licenses. In its notification, Revolut further indicated that the exposed data may have also included verification selfies, account statements, and transaction histories, suggesting a broad scope of potential exposure. The inclusion of identity documents and verification materials is particularly concerning, as these are often key components used in identity theft and further fraudulent activities.
While a Revolut spokesperson acknowledged the incident to TechCrunch, they characterized the number of impacted customers as "limited." The company stated that it had directly contacted all affected individuals. However, Revolut has remained tight-lipped regarding the precise number of customers whose data was compromised. Furthermore, the company declined to specify whether the incident was confined to a particular geographic market or to disclose the identity of the government agency whose email domain was impersonated. This lack of transparency, while understandable in the immediate aftermath of a security breach, has likely fueled further apprehension among users.
"Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information," the spokesperson stated. This admission underscores the advanced nature of the attack, which leveraged the perceived legitimacy of a government entity to bypass standard security protocols. The use of a genuine government email domain is a particularly insidious tactic, as it can easily deceive even vigilant security systems and personnel. Such attacks, often referred to as "spear-phishing" or "whaling," are meticulously planned and executed, targeting specific organizations or individuals with tailored communications designed to elicit a desired response.
In response to the discovery of the scam, Revolut confirmed that it swiftly took action to mitigate further damage. The company stated that it blocked the fraudulent email address immediately upon identifying the unauthorized third party’s activities. Moreover, Revolut has alerted the relevant government agency, law enforcement authorities, and applicable regulatory bodies to the incident. The company was keen to reassure its customer base by emphasizing that "Revolut systems and customer funds are unaffected." This statement aims to distinguish the data breach from an intrusion into the company’s core operational systems or a direct compromise of customer financial assets, though the exposure of PII and identity documents still represents a significant risk to individual users.
London-based Revolut boasts a substantial global customer base, with over 80 million customers worldwide, and operates as a bank in more than 30 countries. This expansive reach means that any security incident, even one affecting a "limited" number of users, can still have widespread implications. The fintech has been on an aggressive growth trajectory, recently expanding its presence in key markets such as India, Mexico, France, and the United Arab Emirates. This global expansion, while indicative of the company’s success, also increases its attack surface and the complexity of its security operations. Adding to its growing footprint, Revolut recently received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank in the United States, with plans to launch in the first half of 2027. This significant development in the U.S. market underscores the company’s ambitions for global financial services dominance.
The news of the data breach was first brought to wider attention by well-known crypto security researcher ZachXBT, who posted about Revolut’s notification to affected customers late on Friday. ZachXBT also noted that the incident appeared to have been specifically targeted at high-net-worth individuals. This detail, if accurate, suggests a more targeted and potentially lucrative motive behind the attack, possibly aiming to gain access to the financial details or identities of wealthier clients for more significant illicit gains. High-net-worth individuals often hold larger sums of money and may possess more sensitive financial information, making them prime targets for sophisticated fraud.
The timing of this data breach is particularly noteworthy, as Revolut is reportedly considering a potential public listing that could value the company at an astonishing $200 billion. This figure represents a significant jump from its private valuation of $75 billion in November. Such a high valuation for an Initial Public Offering (IPO) is ambitious, and any security incident, especially one involving customer data, could cast a shadow over the company’s prospects and investor confidence. Robust data security and a proven track record of protecting customer information are paramount for any financial institution seeking to go public, particularly at such a high valuation. The fintech has also been actively securing banking licenses in Europe and globally, including in France and the UK in recent months, further expanding its regulated operational footprint.
This incident raises critical questions about the security measures in place at Revolut and the broader challenges faced by fintech companies in safeguarding customer data. The reliance on email for legitimate requests, even from government agencies, presents a persistent vulnerability that cybercriminals actively exploit. The incident underscores the need for multi-factor authentication for all sensitive data requests, regardless of the perceived source, and robust internal verification processes that go beyond simply checking an email address. The fact that a seemingly legitimate government email domain was used highlights the sophistication of modern phishing and social engineering attacks, which are constantly evolving to mimic trusted communications.
The implications of this breach extend beyond the immediate financial consequences for Revolut. For the affected customers, the exposure of their personal data and identity documents could lead to long-term risks, including identity theft, fraudulent account openings, and financial loss. It also erodes trust in the digital financial services sector, which relies heavily on customer confidence. Regulators will undoubtedly be scrutinizing Revolut’s response and its security protocols. In the wake of such incidents, regulators often increase oversight and may impose stricter compliance requirements on financial institutions.
The investigation into the exact nature of the scam and the extent of the compromise will be crucial. Understanding how the unauthorized third party obtained access to the government email domain or how they managed to spoof it will be vital in preventing future attacks. It also raises questions about the security practices of the government agency whose domain was compromised. While Revolut has taken steps to mitigate the damage, the long-term impact on customer trust and the company’s future growth, particularly its IPO aspirations, remains to be seen. The incident serves as a stark reminder that in the digital age, data security is not just a technical challenge but a fundamental pillar of trust and operational integrity for any financial service provider. The fintech industry, while innovative and rapidly growing, must remain hyper-vigilant against evolving cyber threats to maintain its credibility and ensure the safety of its users’ sensitive information.

