British fintech company Revolut has confirmed a data breach in which sensitive customer information was disclosed to an unauthorized third party. The incident occurred after the attacker used a legitimate government agency email domain to send fraudulent information requests. According to a notification sent to affected customers and reviewed by TechCrunch, the compromised data included personal identity and contact details such as birth dates, postal and email addresses, phone numbers, and copies of identity documents like passports and driver’s licenses. Additional information potentially exposed includes verification selfies, account statements, and transaction histories.
A Revolut spokesperson told TechCrunch that only a limited number of customers were impacted, though the company did not specify the exact number or whether the breach was confined to a particular region. The spokesperson also declined to identify the government agency involved. Upon discovering the scam, Revolut blocked the fraudulent email address and alerted the relevant government body, law enforcement, and regulators. The company emphasized that its systems and customer funds remain secure.
Revolut, headquartered in London, serves over 80 million customers worldwide and holds banking licenses in more than 30 countries. The fintech has recently expanded into markets such as India, Mexico, France, and the UAE. It also received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank in the United States, expected to launch by mid-2027.
Security researcher ZachXBT noted that the breach appeared to target high net worth individuals. This data exposure comes as Revolut is reportedly considering a public offering that could value the company at up to $200 billion, significantly higher than its $75 billion private valuation last November. The firm continues to grow its banking presence across Europe and globally, having secured recent licenses in France and the UK.