British fintech company Revolut has confirmed that sensitive customer information was disclosed after fraudsters used a legitimate government agency email domain to submit fake information requests.
The incident exposed personal data belonging to a limited number of customers, including dates of birth, postal and email addresses, phone numbers and copies of identity documents.
According to emails sent to affected customers, the exposed documents included passports, driving licences and facial verification images.
Crypto fraud investigator ZachXBT also claimed on Telegram that account statements containing IBANs and transaction histories may have been accessed. He suggested that the incident appeared to have targeted high-net-worth customers, although Revolut has described the number of affected users as limited.
Fraudulent requests bypassed normal verification
A Revolut spokesperson said the company had identified an external impersonation scam in which an unauthorised party used a legitimate government agency domain to send fraudulent requests for customer information.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.
The requests reportedly passed valid technical domain authentication checks, leading Revolut to treat them as genuine legal or regulatory inquiries and process them through its standard compliance procedures.
The company said it has blocked the email address involved and notified relevant regulators and law enforcement agencies.
Revolut also stressed that its internal systems and customer funds were not affected by the incident.
Trusted-domain impersonation raises cybersecurity concerns
The breach highlights the growing risks organisations face when cybercriminals exploit trusted communication channels rather than attempting to directly penetrate a company’s technical infrastructure.
Because the fraudulent requests originated from a legitimate government email domain and passed technical authentication checks, they were more difficult to identify as malicious.
Jake Moore, global cybersecurity advisor at ESET, said the use of a genuine government email account made the requests particularly difficult to detect.
“What makes this particularly worrying is that the requests came from a legitimate government email account, making them far harder to spot as a phishing email,” Moore said.
He added that the attackers were able to disguise themselves as a trusted organisation and simply request the information from Revolut.
“Increasingly, cybercriminals don’t need to break through the technical security controls of a final target if they can impersonate a trusted source,” he said.
Data breach comes amid Revolut’s regulatory expansion
The incident presents an additional challenge for Revolut as the company continues to expand its regulated banking operations.
The fintech recently secured full banking licences in the United Kingdom and Europe following years of engagement with regulators over compliance and governance concerns.
Those concerns have previously included anti-money laundering shortcomings, making the latest data disclosure particularly sensitive from a regulatory and customer trust perspective.
Although Revolut said the breach did not affect its systems or customer funds, the exposure of identity documents and potentially financial account information could raise questions about third-party verification procedures, legal-request authentication and data protection controls.
The incident underscores the need for financial institutions to combine technical email authentication with independent verification processes when handling sensitive customer information, particularly where requests involve identity documents, account statements or transaction records.
Comments