British fintech Revolut recently confirmed that sensitive customer information was disclosed to an unauthorized third party after receiving fraudulent requests sent from what appeared to be a legitimate government email domain. The stolen data included identity and contact details, as well as copies of identity documents such as passports and driver’s licenses. Revolut has not disclosed the exact number of affected customers or the specific government agency involved.
A spokesperson for Revolut stated, “Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.” The company has since blocked the email address, alerted relevant authorities, and stated that its systems and customer funds remain unaffected.
Well-known crypto security researcher ZachXBT posted about Revolut’s email to affected customers, suggesting the incident may have targeted high net worth users. London-based Revolut has over 80 million customers globally and operates as a bank in more than 30 countries, having recently expanded its presence in markets such as India, Mexico, France, and the UAE. Earlier this month, the U.S. Office of the Comptroller of the Currency granted a conditional approval to Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027.
The incident has come as Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November. This expansion comes as the fintech continues to secure banking licenses in Europe and globally.







