Overview
British fintech giant Revolut has confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The incident, described by the company as a "sophisticated external impersonation scam," raises fresh concerns about the vulnerability of financial institutions to social engineering attacks targeting trusted communication channels.
What Data Was Exposed
According to a notification emailed to affected customers and reviewed by TechCrunch, the exposed data included:
- Identity and contact details: birth dates, postal addresses, email addresses, and phone numbers
- Identity documents: copies of passports and driver's licenses
- Potentially additional data: verification selfies, account statements, and transaction histories
A Revolut spokesperson confirmed to TechCrunch that a "limited" number of customers were impacted and stated that the company had contacted those customers directly. However, Revolut declined to disclose the exact number of individuals affected, whether the incident was limited to a specific market, or which government agency was involved.
How the Breach Occurred
In a statement provided to TechCrunch, a Revolut spokesperson explained:
"Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information."
Revolut stated that it blocked the email address after discovering the scam and alerted the relevant government agency, law enforcement, and relevant regulators. The company emphasized that "Revolut systems and customer funds are unaffected."
Targeted at High-Net-Worth Users
The incident was first brought to public attention by well-known crypto security researcher ZachXBT, who posted about Revolut's customer notification email on Telegram late Friday. According to the researcher, the breach appeared to have been specifically targeted at high-net-worth users, suggesting a calculated effort to obtain valuable personal and financial data.
A Critical Juncture for Revolut
The breach comes at a pivotal moment for the London-based fintech, which:
- Serves over 80 million customers globally and operates as a bank in more than 30 countries
- Recently expanded into markets including India, Mexico, France, and the UAE
- Received conditional approval from the U.S. Office of the Comptroller of the Currency in early 2026 to establish a national bank in the United States, with a planned launch in the first half of 2027
- Secured banking licenses in France and the UK in recent months
- Is reportedly weighing a potential IPO that could value the company at as much as $200 billion, up significantly from its $75 billion private valuation in November 2025
Broader Implications
The Revolut incident highlights a growing trend of cybercriminals exploiting legitimate government email domains to circumvent security controls at financial institutions. As fintech companies continue to scale globally and pursue banking licenses in multiple jurisdictions, the pressure to balance customer acquisition with robust security infrastructure becomes increasingly critical.
The timing is particularly sensitive given Revolut's IPO ambitions and U.S. banking expansion plans. How the company manages the aftermath of this breach—including transparency with affected customers and regulators—could have lasting implications for its reputation and growth trajectory.
via TechCrunch
