British fintech company Revolut has revealed that it exposed sensitive customer data to an unauthorized third party following fraudulent information requests sent from a legitimate government agency's email domain. The compromised data included customers' personal identity and contact information such as birth dates, postal and email addresses, phone numbers, and copies of identity documents like passports and driver’s licenses. Additional data potentially accessed included verification selfies, account statements, and transaction histories.

Revolut confirmed that only a limited number of customers were affected and that those individuals have been contacted directly. The company did not specify the exact number of impacted users, the geographic scope of the breach, or the government agency involved. A spokesperson described the incident as a sophisticated impersonation scam where an unauthorized party exploited a legitimate government email domain to submit fraudulent data requests.

Upon discovering the scam, Revolut blocked the email address used, notified the relevant government agency, law enforcement, and regulatory bodies. The company emphasized that its internal systems and customer funds remain secure.

Revolut, which serves over 80 million customers worldwide and operates as a bank in more than 30 countries, has recently expanded into markets including India, Mexico, France, and the UAE. The firm also received conditional approval to establish a national bank in the U.S., expected to launch by mid-2027.

Security researcher ZachXBT noted that the breach appeared to target high net worth customers. This incident emerges as Revolut considers a potential public offering that could value the company at up to $200 billion, significantly higher than its $75 billion private valuation last November. The fintech has been actively growing its banking licenses across Europe and globally in recent months.