British fintech Revolut confirmed it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.
The exposed data included customers' identity and contact details, including birth date, postal and email addresses, and phone numbers, as well as copies of identity documents such as passports and driver's licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may also have included verification selfies, account statements, and transaction histories, the firm said in its notification.
A Revolut spokesperson confirmed to TechCrunch that a "limited" number of customers were impacted and said the company had contacted those customers directly. Revolut did not disclose the exact number of impacted individuals, did not answer whether the incident was limited to a specific market, and declined to disclose the government agency involved.
"Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the spokesperson said.
Revolut told TechCrunch it blocked the email address after discovering the scam and alerted the relevant government agency, law enforcement, and relevant regulators, adding that "Revolut systems and customer funds are unaffected."



