British fintech company Revolut has disclosed a data breach resulting from fraudulent requests sent using a legitimate government agency email domain. The breach exposed sensitive customer information such as identity and contact details, including birth dates, postal and email addresses, phone numbers, and copies of identity documents like passports and driver’s licenses. Additional data potentially compromised includes verification selfies, account statements, and transaction histories.

Revolut confirmed that only a limited number of customers were affected and that those impacted were contacted directly. The company did not specify the exact number of individuals involved or whether the breach was confined to a particular market. The identity of the government agency whose email domain was used was also not disclosed.

According to a company spokesperson, the incident involved a sophisticated impersonation scam where an unauthorized party exploited a legitimate government email domain to submit fraudulent information requests. Upon discovery, Revolut blocked the email address, notified the relevant government agency, law enforcement, and regulators. The company emphasized that its systems and customer funds remain secure.

Revolut serves over 80 million customers worldwide and operates as a bank in more than 30 countries. The firm has been expanding its presence in markets such as India, Mexico, France, and the UAE. Recently, it received conditional approval from the U.S. Office of the Comptroller of the Currency to establish a national bank in the United States, expected to launch by mid-2027.

Security researcher ZachXBT noted that the breach appeared to target high net worth users. This incident occurs as Revolut considers a public listing that could value the company at up to $200 billion, a significant increase from its $75 billion private valuation in late 2023. The fintech has also been actively securing banking licenses across Europe and globally.