Revolut Confirms Customer Data Breach Through Fake Government Requests
British fintech Revolut has confirmed a Revolut data breach after unauthorized attackers used a fake government agency email domain to trick the company into handing over sensitive customer information.
According to a notification sent to affected customers and reviewed by TechCrunch, the exposed data included identity and contact details such as birth dates, postal and email addresses, and phone numbers, along with copies of identity documents including passports and driver’s licenses. Revolut also said the breach may have exposed verification selfies, account statements, and transaction histories for some affected users.
How the Revolut Data Breach Happened
A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were affected and said the company had reached out to them directly. However, Revolut declined to share the exact number of people impacted, wouldn’t confirm whether the breach was limited to a specific market, and refused to name the government agency whose identity was impersonated.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.
The company said it blocked the fraudulent email address as soon as the scam was discovered and has since alerted the relevant government agency, law enforcement, and applicable regulators. Revolut emphasized that its core systems and customer funds remain unaffected by the breach, framing the incident as isolated to data exposure rather than financial theft.
Who Revolut Is and Why This Breach Matters
London-based Revolut serves more than 80 million customers globally and operates as a licensed bank in more than 30 countries. The company has been expanding aggressively in recent months, rolling out services in markets including India, Mexico, France, and the UAE.
That expansion recently reached a major milestone in the US. Earlier this month, the Office of the Comptroller of the Currency granted Revolut conditional approval to establish a national bank in the country, with the company expecting to launch stateside sometime in the first half of 2027.
A High-Value Target
Well-known crypto security researcher ZachXBT publicly shared Revolut’s breach notification email late Friday, noting that the incident appeared specifically targeted at high net worth users rather than a broad, indiscriminate attack. That detail suggests the attackers behind the impersonation scheme may have had specific customers in mind rather than simply casting a wide net.
The timing of the breach adds another layer of scrutiny for the company. Revolut is reportedly weighing a potential public listing that could value the fintech at as much as $200 billion, a significant jump from its $75 billion private valuation set just last November. Any security incident involving customer data carries added weight for a company actively courting public market investors and regulatory approval across multiple jurisdictions simultaneously.
Part of a Broader Banking Push
Beyond its pending US approval, Revolut has continued expanding its formal banking footprint across Europe, having secured banking licenses in both France and the UK in recent months. That regulatory expansion means the company is increasingly subject to stricter oversight in the markets where it operates, oversight that will likely intensify in the wake of this latest disclosure.
For now, Revolut maintains that the breach was contained to a limited group of customers and that its underlying financial systems remain secure. Still, the incident highlights a growing risk facing major financial institutions: sophisticated social engineering attacks that exploit trusted government channels rather than attempting to breach technical systems directly, a tactic that can be considerably harder to detect and prevent through traditional cybersecurity defenses alone.
Affected customers should watch closely for phishing attempts or identity theft in the weeks ahead, since data exposed in the Revolut data breach can be used for follow-up scams well after the initial incident is contained.

