Loading...

Revolut Confirms Data Breach From Fake Government Requests

Key takeaways

  • Revolut confirmed that fraudulent requests sent from a legitimate government email domain duped the company into sharing customer identity documents and transaction histories with an unauthorized third party.
  • The fintech refused to disclose the exact number of affected customers, the specific government agency impersonated, or whether the incident was limited to particular markets.
  • The breach highlights a systemic vulnerability in how financial institutions authenticate information requests, even as Revolut pursues U.S. banking expansion and a potential public listing valued at $200 billion.

British fintech Revolut disclosed a sophisticated data breach after fraudulent requests sent through a legitimate government agency email address tricked the company into handing over sensitive customer information to an unauthorized third party. The incident exposes a vulnerability in email-based verification processes that even regulated financial services companies struggle to defend against.

Revolut confirmed the breach through notifications sent to affected customers, reviewed by TechCrunch. The company said it had taken action to block the attacker’s email address and alerted law enforcement and relevant regulators, while emphasizing that its systems and customer funds remained secure.

How Revolut’s Customer Data Reached an Unauthorized Third Party

The impersonation attack

The breach centered on a social engineering campaign that exploited fundamental trust in institutional email addresses. An attacker created fraudulent requests using a legitimate government agency’s email domain—the specific agency involved remains undisclosed by Revolut. The fintech received multiple requests bearing what appeared to be official government credentials and responded by providing customer information without detecting the deception.

A Revolut spokesperson described the attack as “a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” The fintech blocked the offending email address immediately after identifying the fraud and notified the relevant government agency, law enforcement, and regulators.

What information was compromised

The exposed data included fundamental identity information: birth dates, postal addresses, email addresses, and phone numbers. The breach encompassed copies of identity documents used during account verification—passports and driver’s licenses—along with verification selfies, account statements, and transaction histories. The full scope varied by customer, but the combination of identity and financial data creates substantial risk for account takeover and identity theft.

Revolut Confirms Data Breach From Fake Government Requests

Scale and Scope Remain Largely Unknown

Revolut refused to specify how many customers fell victim to the breach, stating only that a “limited” number were affected. The company did not disclose whether the incident targeted a particular geographic market or customer segment, though crypto security researcher ZachXBT suggested the attacks were concentrated on high net worth users.

Revolut serves over 80 million customers globally and holds banking licenses in more than 30 countries. The company has been expanding aggressively, recently entering India, Mexico, France, and the United Arab Emirates. Even a “limited” breach among this customer base raises questions about the actual number of exposed records and whether the company’s characterization minimizes the incident’s scope.

Revolut’s Containment and Communication Strategy

The fintech discovered the scam and moved quickly to contain it. Beyond blocking the attacker’s email address, Revolut alerted law enforcement, relevant regulators, and the legitimate government agency whose domain was abused. In its notification to affected customers, Revolut emphasized that neither its systems nor customer funds had been compromised—a technical distinction that matters for regulatory purposes but offers little comfort to customers whose identity documents are now in unauthorized hands.

Revolut contacted affected customers directly about the breach but did not make a public statement until questions from TechCrunch forced confirmation of the incident. The company’s communication strategy treated this as a limited, customer-specific disclosure rather than a material security event warranting broad notification or transparency about scale.

A Sector-Wide Problem With Email Verification

Why email remains too trusted in finance

Financial institutions rely heavily on email verification for high-stakes requests, yet email remains trivially spoofable at scale. An attacker leveraging a genuine government domain—not a lookalike address, but the authentic domain itself—exploits the asymmetry between how quickly humans trust official-looking credentials and how difficult it is to reverse that decision once information has been disclosed. This vulnerability cuts across the entire sector. Large banks, payment processors, and fintech companies all receive emails claiming to come from regulators, law enforcement, and government agencies requesting customer information. Most verify these requests through out-of-band communication channels, but Revolut’s case suggests at least some requests slipped through without that additional check.

The timing of the attack also mattered. Regulators worldwide issue increasingly complex information requests to financial firms, making it plausible that Revolut received an email matching patterns it expected. An attacker familiar with the fintech industry could craft requests aligned with known regulatory inquiries, making them harder to distinguish from legitimate ones at first glance. The specificity required to abuse a government domain also suggests the attacker possessed either access to that agency’s email system or deep knowledge of how financial institution authentication processes work.

Expansion Plans Amid Security Scrutiny

U.S. banking expansion and regulatory review

Revolut’s disclosure comes as the company pursues an aggressive expansion agenda. The U.S. Office of the Comptroller of the Currency granted conditional approval for Revolut to establish a national bank, with the company expecting to launch by the first half of 2027. This milestone represents a significant step toward mainstream American banking presence, though it also means heightened regulatory scrutiny going forward.

Public market valuation and disclosure obligations

The company is also reported to be weighing a public listing that could value it at as much as $200 billion—a substantial jump from its $75 billion private valuation in November. Any IPO would likely trigger extensive disclosure of historical security incidents and controls, potentially making this breach a subject of investor and regulatory attention. Recent banking license approvals in France and the United Kingdom add additional regulatory oversight, with European authorities now directly supervising Revolut’s operations. This expanded regulatory footprint means future security disclosures must satisfy multiple jurisdictions’ notification and reporting requirements.

Implications for Customers and Competitors

For Revolut specifically, the breach tests its credibility at a pivotal moment. A fintech seeking national bank status in the United States and a potential public listing cannot afford recurring security incidents. Regulators evaluating the conditional approval will consider whether Revolut’s controls are adequate for a regulated bank, and this breach raises questions about authentication processes for high-stakes information requests.

Broader implications extend to how financial institutions vet external requests for customer data. Email verification, even when coupled with surface-level credential checks, remains insufficient. The incident underscores that attackers sophisticated enough to leverage legitimate government email domains can bypass processes that most institutions consider adequate. The fact that the breach appeared to target high net worth customers adds another dimension, suggesting a deliberate, intelligence-driven campaign rather than mass-scale indiscriminate attacks. Revolut’s ability to communicate transparently about the incident and remediation steps will significantly influence how customers and regulators assess its security posture as the company pursues its most ambitious growth plans yet.

Frequently Asked Questions

What personal information was exposed in the Revolut breach?

The exposed data included birth dates, postal and email addresses, phone numbers, copies of identity documents like passports and driver's licenses, and possibly verification selfies, account statements, and transaction histories.

How did the attacker gain access to customer data?

An unauthorized third party sent fraudulent information requests using a legitimate government agency email domain, which Revolut responded to without detecting the impersonation until after the data had been disclosed.

How many Revolut customers were affected by the breach?

Revolut confirmed only a limited number of customers were impacted but refused to disclose the exact number, whether the breach was geographically limited, or which government agency was impersonated.

Written by
Nathan Cole

Nathan Cole covers financial markets — equities, exchange rates, and monetary policy. He tracks central bank decisions and explains what each rate move actually means for everyday investors.