Skip to content
Tech News
← Back to articles

Revolut confirms customer data breach through fake government requests

read original get Yubico YubiKey 5C NFC Security Key → more articles
Why This Matters

Revolut, a fintech with more than 80 million customers, handed over sensitive KYC data — including passports, driver's licenses, selfies, and transaction histories — to scammers who submitted fake legal requests from a legitimate government agency email domain. The incident highlights how the trust-based process behind law enforcement data requests remains a soft target that no amount of systems security can patch. It lands as Revolut pushes into new markets and pursues a U.S. national bank charter.

Key Takeaways
Worth a Look

Yubico YubiKey 5C NFC Security Key — When breaches expose your identity documents and contact details, phishing and account-takeover attempts usually follow — a hardware security key makes your logins far harder to hijack. The YubiKey 5C NFC works over USB-C or by tapping on your phone, and it's supported by major banking, email, and password manager accounts. It's a small, durable piece of kit to keep on your keyring for everyday two-factor logins.

See Yubico YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.

The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification.

A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.

“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.

Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party and alerted the relevant government agency, law enforcement, and relevant regulators, adding, “Revolut systems and customer funds are unaffected.”

London-based Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries, per its website. The fintech recently expanded its presence in markets including India, Mexico, France, and the UAE. Moreover, earlier this month, the U.S. Office of the Comptroller of the Currency granted a conditional approval to Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027.

Well-known crypto security researcher ZachXBT posted about Revolut’s email to its affected customers late on Friday. The researcher said the incident appeared to have been targeted at high net worth users.

The incident comes as Revolut reportedly weighs a potential public listing that could value it at as much as $200 billion, up from its $75 billion private valuation in November. The fintech has also been expanding its banking footprint in Europe and globally, securing banking licenses in France and the UK in recent months.