British fintech firm Revolut has confirmed a data breach after an unauthorized third party used fake government agency emails to trick employees into handing over customer information. Speaking to Infosecurity on September 14, a company spokesperson described the incident as "a sophisticated external impersonation scam" in which fraudulent information requests were submitted using a legitimate government agency domain email. The threat actors exploited valid technical domain authentication, leading Revolut employees to fulfill the requests as routine legal compliance.
The compromised information includes customers' full names, birth dates, home addresses, phone numbers, email addresses and job titles, according to independent crypto-security researcher ZachXBT, who issued a warning about the breach on September 12 via Telegram. The exposed data also reportedly contains copies of government-issued identification documents such as passports and driver's licenses, along with verification selfies. Financial details were also accessed, including IBANs, account-opening dates, complete transaction and withdrawal histories, and Bitcoin wallet reference numbers. Revolut said only a "very limited group of customers" were affected and that its systems and customer funds remained secure, though the company declined to specify the exact number of victims or which markets were impacted.
Revolut's security team immediately blocked the fraudulent email address upon discovering the breach, notified affected customers, and alerted the relevant government agency as well as enforcement agencies, data protection authorities, and financial regulators, the spokesperson said. Muhammad Yahya Patel, vCISO and cybersecurity advisor at Huntress, questioned why a regulated financial institution managing highly sensitive data "didn't have sufficiently rigorous verification controls to catch it," noting that for a fintech built on digital identity verification, the standard for verifying third-party data requests should be exceptionally high.
Security experts warn the scope of exposed information creates severe risks beyond typical data breaches. Patel described the compromised data as "not a data leak, that's a complete identity theft kit handed to whoever sent those fraudulent requests," citing the combination of passports, driver's licenses, verification selfies, account statements, transaction histories, birth dates, and addresses. Jamie Akhtar, CEO and co-founder of CyberSmart, cautioned that while customer funds and systems weren't affected, the exposed information could be weaponized for identity fraud and highly targeted phishing attacks. The report notes that affected customers should be especially wary of unexpected calls, emails, or messages purporting to come from Revolut, government bodies, or other trusted organizations, and should never share passwords, passcodes, or one-time security codes.
Akhtar recommended affected users contact Revolut only through its official app or verified website, and advised all digital financial service users to enable multi-factor authentication, use unique passwords, monitor accounts and credit reports for unusual activity, and report suspected identity misuse promptly. The incident highlights how social engineering attacks that impersonate legitimate authorities can bypass technical security controls by exploiting human compliance with legal and regulatory processes. For financial institutions managing sensitive identity and transaction data, the breach underscores tension between operational efficiency in responding to lawful requests and implementing verification layers robust enough to detect sophisticated impersonation attempts.

