Financial technology and banking company Revolut has disclosed that sensitive customer data was exposed after receiving a fraudulent request that appeared to originate from a government agency. The compromised data included copies of passports, verification selfies, and full transaction histories.
According to a post by International Cyber Digest on X, the requests for customer information were sent from a legitimate government agency email domain and successfully passed Revolut's authentication checks. Revolut later determined that the requests were not authentic and notified the affected customers on Friday.
A Revolut spokesperson confirmed the incident on Saturday, stating that the firm recently identified a sophisticated external impersonation scam in which an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent information requests. Upon detecting the issue, Revolut blocked the address, alerted the relevant government agency, and notified law enforcement agencies and financial regulators.
The spokesperson emphasized that Revolut's systems and customer funds remain unaffected, noting that the company directly contacted the limited number of impacted individuals to provide support.
Crypto researcher ZachXBT reportedly commented that he believed the incident was limited in scope and targeted high-net-worth users. The breach also drew criticism on social media regarding mandatory customer identification protocols, with user Marc Zeller publicly noting that the event served as a reminder of the risks associated with data collection.


