WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
ShopCartAccount
Advertisement

Revolut Confirms Customer Data Breach Through Fake Government Email Requests

Revolut confirms customer data breach after falling for fake government email requests, exposing IDs, selfies, and account info.

By mitch·5 min read
A cracked computer screen glows red with scattered digital data fragments floating around.

Revolut has confirmed that it handed over customer data to an unauthorized third party after falling for a fake government email request. The British fintech said a “limited” number of customers were affected, but it would not say exactly how many.

The company emailed affected customers to notify them of the breach. TechCrunch reviewed the notification and reported on it. Revolut’s spokesperson confirmed the incident to TechCrunch.

What Got Exposed

The breached data included customers’ identity and contact details. That means birth dates, postal addresses, email addresses, and phone numbers were handed over. Copies of identity documents were also exposed, including passports and driver’s licenses.

Advertisement

The notification said the data may have also included verification selfies, account statements, and transaction histories. Revolut did not confirm which of those items were definitely exposed.

A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.

“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.

How the Scam Worked

The scam involved an unauthorized third party using a legitimate government agency email domain to send requests for information. Revolut received those requests and responded to them, handing over the data in the process.

The company blocked the email address after discovering the scam from the unauthorized third party. Revolut then alerted the relevant government agency, law enforcement, and relevant regulators.

“Revolut systems and customer funds are unaffected,” the spokesperson added.

The fact that Revolut did not disclose the government agency involved is notable. The company has not named the agency, nor has it said whether the incident was limited to a specific market.

The Scale of the Problem

Revolut is a large company. It has more than 80 million customers globally and operates as a bank in more than 30 countries, according to its website. The company is headquartered in London.

The breach comes at a busy time for Revolut. The fintech recently expanded its presence in markets including India, Mexico, France, and the UAE. Earlier this month, the U.S. Office of the Comptroller of the Currency granted a conditional approval to Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027.

The company’s recent growth has brought new regulatory scrutiny. Its expansion into Europe and globally has seen it secure banking licenses in France and the UK in recent months.

Who Got Targeted

One researcher believes the breach was aimed at high net worth users. ZachXBT, a well-known crypto security researcher, posted about Revolut’s email to its affected customers late on Friday. The researcher said the incident appeared to have been targeted at high net worth users.

ZachXBT’s assessment is based on his reading of the situation.

The Listing Question

Revolut is reportedly weighing a potential public listing. The reported valuation is as much as $200 billion, up from its $75 billion private valuation in November.

A data breach of this kind will not help the company’s case with investors. The incident shows a vulnerability in Revolut’s systems, and the fact that the company did not disclose the number of affected customers or the government agency involved raises questions about transparency.

The Response So Far

Revolut’s official statement was measured. The company said its systems and customer funds are unaffected, which is a key point for customers who are worried about financial loss.

The company has contacted affected customers directly, according to the spokesperson. It has also taken steps to block the email address and alert authorities.

Key Facts Box

  • Company: Revolut, a British fintech
  • Customers: More than 80 million globally, operating in more than 30 countries
  • Incident: Data breach through fake government email requests
  • Exposed data: Identity and contact details, including birth dates, addresses, phone numbers, passports, driver’s licenses; verification selfies, account statements, transaction histories may have been included
  • Government agency: Not disclosed by Revolut
  • Affected customers: Described as a “limited” number, exact count not given
  • Listing valuation: Reported as much as $200 billion, up from $75 billion private valuation in November
  • Regulatory approval: Conditional approval from the U.S. Office of the Comptroller of the Currency for a national bank, expected to launch in the first half of 2027

The breach is a reminder that even large companies with global operations are vulnerable to social engineering attacks. A legitimate-looking email address was enough to trick Revolut into handing over data.

The company has responded quickly by blocking the email address and alerting authorities. Whether that response will be enough to restore customer confidence remains to be seen.

For now, affected customers should watch their accounts closely and consider changing passwords and other security settings. Revolut has said it has contacted those customers directly, but the company has not provided a full picture of what happened.

The incident is a wake-up call for the fintech industry. Companies need to be vigilant about phishing attempts and to have robust processes in place to verify requests before responding to them.

The data exposure is concerning. Identity documents, verification selfies, account statements, and transaction histories are the kinds of details that can be used for identity theft or fraud, though Revolut has not confirmed which of these items were definitely exposed.

Revolut’s systems and customer funds are unaffected, according to its statement. That is the good news. The bad news is that the company has not disclosed the number of affected customers or the government agency involved, which raises questions about transparency.

The breach comes at a difficult time for the company. Revolut is trying to build trust with customers while expanding into new markets and preparing for a possible public listing.

The company’s future plans remain unchanged. The national bank in the U.S. is still expected to launch in the first half of 2027.

The road ahead for Revolut will depend on how it handles the fallout.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.