British fintech company Revolut has confirmed a data breach involving the unauthorized disclosure of sensitive customer information. The incident occurred after the company received fraudulent requests for data sent from an email address using a legitimate government agency domain. The compromised information included customers’ personal identity details such as birth dates, postal and email addresses, phone numbers, and copies of identity documents like passports and driver’s licenses. Additional data potentially exposed included verification selfies, account statements, and transaction histories.

Revolut informed affected customers directly but did not specify the exact number of individuals impacted or the particular government agency involved. A company spokesperson described the event as a "sophisticated external impersonation scam" and confirmed that the fraudulent email address was blocked promptly upon discovery. Revolut also notified law enforcement, the relevant government agency, and regulatory bodies. The company emphasized that its internal systems and customer funds were not compromised.

With over 80 million customers worldwide and banking operations in more than 30 countries, Revolut has been expanding its global presence, including recent moves into India, Mexico, France, and the UAE. The firm also received conditional approval to establish a national bank in the United States, expected to launch by 2027.

Security experts noted that the breach appeared to target high net worth users. The incident emerges as Revolut considers a potential public offering that could value the company at up to $200 billion, significantly higher than its previous private valuation. The fintech has recently secured banking licenses in key European markets, underscoring its growth ambitions.