British fintech firm Revolut has revealed that it disclosed sensitive customer data to an unauthorized third party following fraudulent information requests sent from a legitimate government agency email domain. The compromised information included customers’ personal identity and contact details such as birth dates, postal and email addresses, phone numbers, and copies of identity documents like passports and driver’s licenses. Additional data potentially exposed included verification selfies, account statements, and transaction histories.

Revolut confirmed the breach affected a limited number of customers but did not specify the exact number or whether the incident was confined to a particular market. The company also declined to identify the government agency whose email domain was impersonated.

A Revolut spokesperson described the incident as a sophisticated external impersonation scam involving fraudulent requests submitted via a legitimate government email domain. Upon discovery, Revolut blocked the email address used in the scam and notified the relevant government agency, law enforcement, and regulatory bodies. The company emphasized that its internal systems and customer funds remained secure.

Revolut, headquartered in London, serves over 80 million customers worldwide and operates as a bank in more than 30 countries. It has recently expanded into markets such as India, Mexico, France, and the UAE. Additionally, Revolut received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank in the United States, expected to launch by mid-2027.

Security researcher ZachXBT noted that the breach appeared to target high net worth users specifically. This incident comes amid Revolut’s ongoing efforts to expand its banking services globally and its consideration of a potential public listing that could value the company at up to $200 billion, a significant increase from its $75 billion private valuation last November.