Revolut confirms it handed customer data to scammers posing as government agency
The data reportedly includes copies of identity documents, such as passports and driver’s licenses, as well as complete transaction histories.

Image via Shutterstock
- Scammers obtained Revolut customer data using an email address on a legitimate government agency domain.
- Exposed data included contact details, birth dates, occupations, and identity documents.
- Reports say verification selfies, account statements, transaction histories, IBANs, and Bitcoin transactions may also be affected.
- Revolut says it blocked the address, alerted authorities, and says customer funds remain unaffected.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
It’s not just ordinary people who fall for scams – major companies can be fooled, too. British fintech Revolut confirmed it disclosed sensitive customer information after receiving fraudulent data requests from what appeared to be a legitimate government agency email account.
"Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators," a spokesperson told Reuters on Saturday.
The compromised data included customers' birth dates, postal and email addresses, occupation, and phone numbers, as well as copies of their identity documents, including passports and driver’s licenses, according to reports.
TechCrunch reported that verification selfies, account statements, and transaction histories may also have been included. According to a separate report, the compromised data included IBANs, withdrawal records, and complete transaction histories, as well as Bitcoin transactions.
One affected person shared the email received from Revolut on X, complaining that the breach came right after Revolut sent him a notification “to provide a LOT of data or ‘we will close your account in 20 days’”.
The exact number of those affected is undisclosed, but a spokesperson told TechCrunch that the breach impacted a “limited” number of customers, who had been contacted directly.
"Revolut systems and customer funds are unaffected," the spokesperson added.
The attack was described as “a sophisticated external impersonation scam” involving an email address on a legitimate government agency domain used to submit fraudulent requests for information. The name of the agency was not released.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Founded in 2015, Revolut serves more than 80 million retail customers and around 800,000 business clients and was valued at $115 billion in a secondary share sale launched in July.
In July, an attacker claimed to be selling 75 million Revolut customer records, including card details, emails, names, phone numbers, addresses, device details, and hashed credentials. Revolut said at the time that it found no evidence of a breach, and Cybernews researchers believe the information was aggregated from multiple sources.