Revolut Exposed Customer Data via Fake Government Email Scam

London-based fintech giant Revolut has confirmed a security breach after customers’ sensitive personal data was disclosed to an unauthorized party. The leak occurred when impostors used a legitimate government agency’s email domain to send fraudulent data requests. Revolut only learnt of the scam after some of those requests were approved.

The compromised data set includes names, birth dates, address information (postal, email, phone), and copies of identity documents like passports and driver’s licenses. Affected customers may also have had further information exposed, such as verification selfies, account statements, and transaction histories. The company has said the number of impacted customers was “limited” but has not revealed an exact figure.

The company responded by blocking the fraudulent email address and notifying the real government agency, law enforcement, and regulators. Revolut insists customer funds and the security of its systems have not been affected. They have also reached out directly to those whose information was exposed.

Revolut serves over 80 million customers worldwide, operating as a bank in more than 30 countries. In recent months it has expanded into markets such as India, Mexico, France, and the UAE. In the US, its plan to open a national bank received conditional approval from regulators, expected to launch in the first half of 2027.

External security analysts suggest the breach may have been aimed at high net worth users. The incident comes as Revolut is reportedly preparing for a possible public listing that could value the company at as much as $200 billion, a jump from its $75 billion private valuation in late 2025.

Why this matters: This breach isn’t a data leak via system vulnerability — instead, it exploited a trusted third party’s identity, namely a government agency’s email domain. That makes anti-phishing safeguards, strict verification of email provenance, and secure request handling essential. For Revolut, now is a critical time: as financial-first fintechs grow globally, users demand not only convenience but trust. Regulators will likely scrutinize how these identity-based fraud schemes are detected and handled — especially when expansion into heavily regulated markets like the US is underway.