Fraudulent requests prompted disclosure

Revolut has confirmed that it disclosed sensitive customer information to an unauthorized party after receiving fraudulent requests sent through a legitimate government-agency email domain. The company described the incident as an external impersonation scam and said its own systems and customer funds were not compromised.

The incident was reported on September 13 after TechCrunch reviewed a notification sent to affected customers and obtained confirmation from a Revolut spokesperson. The company said only a limited number of customers were involved, but it did not provide a total, identify the government agency whose email domain was used, or say whether the exposure was confined to one market.

According to the customer notice, the disclosed material included identity and contact information such as dates of birth, postal addresses, email addresses and telephone numbers. Copies of passports or driving licences were also among the affected records. Depending on the customer, the exposed data may additionally have included identity-verification selfies, account statements and transaction histories.

Revolut said it blocked the email address connected to the requests once the deception was found. It also notified the relevant agency, law-enforcement authorities and financial regulators, and contacted affected customers directly. The company’s statement distinguishes the event from an intrusion into its banking platform: it says the disclosure was induced by requests that appeared to originate from a trusted government domain.

Scope remains undisclosed

The use of a genuine agency email domain raises questions that Revolut’s public account does not yet answer, including how the sender gained control of the address and what checks were applied before customer information was released. The supplied reporting does not establish whether the agency itself suffered a broader compromise. Revolut has not named the jurisdiction involved.

The distinction matters for customers assessing their exposure. Identity documents and contact details can support follow-on impersonation or phishing attempts even when account credentials and funds remain secure. Transaction records and statements can also reveal financial relationships and patterns. Revolut’s notice, however, did not say that every listed category was exposed for every affected person.

Revolut says it serves more than 80 million customers worldwide and operates as a bank in more than 30 countries. That scale makes the undisclosed number and geographic distribution of affected customers important details still awaiting clarification. For now, the verified account is limited to the company’s acknowledgement, the categories of data described in its notification and the response steps it says it took.

Affected customers should rely on communications delivered through verified Revolut channels and be cautious about unexpected messages that refer to identity checks or recent transactions. The company has not reported a loss of customer funds in connection with this incident.