Revolut has confirmed that sensitive customer information was disclosed to an unauthorized third party after fraudulent information requests were sent from an email account operating inside a legitimate government agency domain. The incident exposed identity and financial records belonging to a limited number of customers, while Revolut said its internal systems and customer funds were not compromised.
According to TechCrunch’s report on the incident, the exposed information included names, birth dates, postal and email addresses, phone numbers and copies of passports or driver’s licenses. Some affected records may also have included verification selfies, account statements and transaction histories. The disclosure resulted from a sophisticated impersonation scheme rather than attackers directly breaching Revolut’s core infrastructure.
Fake Government Requests Bypassed Trust Controls
Revolut said the attacker used a legitimate government agency email domain to submit fraudulent requests for customer information. The attack exploited trust in an apparently authentic government communication channel, demonstrating how social engineering can bypass security procedures without requiring direct access to banking systems.
Once Revolut identified the requests as fraudulent, the company blocked the email address and notified the relevant government agency, law enforcement, data-protection authorities and financial regulators. Revolut said it contacted affected customers directly but has not disclosed how many people were involved or which jurisdictions were impacted.
The financial information involved creates a particularly sensitive risk profile. Transaction histories combined with identity documents, addresses and contact information could make affected customers more vulnerable to targeted phishing, impersonation and account-recovery fraud. For customers whose crypto activity appeared in disclosed records, the breach can also connect identifiable personal information with financial behavior.
Revolut Says Customer Funds Remain Secure
Revolut has emphasized that the incident did not compromise its systems or customer balances. The confirmed exposure involves information improperly disclosed in response to fraudulent requests, not evidence that attackers obtained direct control over Revolut accounts or crypto holdings.
Claims circulating online that attackers obtained tens of millions of records or issued a large Bitcoin ransom demand remain unverified by Revolut and were not substantiated in the reliable reporting reviewed. Those allegations should therefore remain separate from the confirmed breach until additional evidence or an official investigation establishes their accuracy.
For Revolut and other financial institutions, the incident exposes a security challenge that extends beyond conventional network defenses. When attackers can abuse trusted government or third-party communication channels, verification procedures surrounding sensitive data requests become as important as protecting the underlying banking infrastructure.
