· via TechCrunch
Revolut breach: fraudsters used real government email domain to get customer data
Revolut says an unauthorized third party obtained customer identity documents and contact details by submitting fraudulent information requests from a legitimate government email domain.

What happened
Revolut has confirmed that it handed sensitive customer information to an unauthorized third party after being deceived by fraudulent information requests that came from a genuine government email domain, TechCrunch reports.
The company described the scheme as a "sophisticated external impersonation scam" in which an attacker used an email address on a real government agency domain to submit bogus demands for customer data. Because the messages originated from an actual government domain rather than an obvious lookalike, they would have been hard to catch with standard sender checks.
A Revolut spokesperson told TechCrunch that a "limited" number of customers were affected and had been contacted directly. The firm declined to say how many people were involved, whether the incident was confined to a specific market, or which government agency's domain was abused.
What data was exposed
In a notification emailed to affected customers and reviewed by TechCrunch, Revolut said the disclosed material included identity and contact details such as dates of birth, postal and email addresses, and phone numbers. Copies of identity documents, including passports and driver's licenses, were also handed over.
The company added that the data may have extended to verification selfies, account statements, and transaction histories.
Revolut stressed that its systems and customer funds were unaffected. In other words, this was not an infrastructure compromise: the data left through the company's own process for responding to official information demands, after that process was tricked.
Revolut's response
According to the company, once the scam was discovered it blocked the responsible email address and alerted the government agency involved, law enforcement, and the relevant regulators.
The independent crypto security researcher known as ZachXBT publicized the customer notification late on Friday, and said the campaign appeared to target high net worth users. If that reading is correct, the attacker was hunting for accounts with large balances rather than scooping up customers at random, which fits a pattern of tailored social engineering against valuable individuals.
A sensitive moment for the fintech
The disclosure lands at an awkward point in Revolut's trajectory. The London-based company says it has more than 80 million customers and operates as a bank in over 30 countries, with recent expansion into markets including India, Mexico, France and the UAE. Earlier this month the U.S. Office of the Comptroller of the Currency granted conditional approval for Revolut to establish a national bank in the United States, which the firm expects to launch in the first half of 2027.
Revolut is also reportedly weighing a public listing that could value it at as much as $200 billion, up from the $75 billion private valuation it reached in November, and it has secured banking licenses in France and the UK in recent months. A single incident is unlikely to derail those plans, but it invites scrutiny of internal data-handling controls at exactly the moment regulators on both sides of the Atlantic are paying closer attention.
Why it matters
The weakest link here was a process, not a system. Revolut's infrastructure stayed intact; the attacker simply persuaded someone that a fraudulent request was a lawful one. A verified government domain is not proof of authority — a compromised or misused official mailbox looks identical to a legitimate one.
For any organization that fulfills law-enforcement or regulatory data demands, the lessons are concrete: verify requests through an independent, out-of-band channel; require positive confirmation with the requesting agency before releasing documents; and treat urgent, high-pressure requests with the same skepticism applied to phishing. Out-of-band verification is the single control that would likely have stopped this.
For the customers involved, the combination of passport or license copies, contact details, selfies and transaction histories is close to a complete identity-theft kit. They should assume follow-on fraud is possible — phishing, account-takeover attempts at other services, impersonation — rather than treat the notification as the end of the matter.
- #security
- #data-breach
- #fintech
- #phishing
- #revolut