
Revolut disclosed personal and financial information of customers after receiving fraudulent information requests sent from an email account hosted on a legitimate government agency domain.
The fintech company says its systems and customer funds were not compromised.
Blockchain investigator ZachXBT brought the incident to public attention by sharing on Telegram a notification Revolut sent to an affected customer. CyberInsider subsequently contacted Revolut for additional information about the incident.
“Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information,” a Revolut spokesperson told CyberInsider.
According to the notification shared by ZachXBT, the fraudulent request appeared to originate from a legitimate government agency and passed the technical checks normally associated with that agency's email domain. Revolut therefore treated it as an authentic government information request and fulfilled it.

ZachXBT
Revolut is a UK-headquartered financial technology company providing digital banking, payments, cryptocurrency trading, and other financial services through its mobile platform. Like other regulated financial institutions, it must respond to valid requests for customer information from law enforcement and government agencies.
The compromised information appears extensive. Revolut's notification states that data provided in response to the fraudulent request included customer:
- Full names
- Dates of birth
- Occupations
- Postal addresses
- Email addresses
- Telephone numbers
- Copies of ID documents (passports, driver’s licenses)
- Facial verification selfies
- Financial information (IBANs, account status, account opening dates, wallet reference numbers, withdrawal records and complete transaction histories)
Revolut told affected users that no biometric facial telemetry was involved or compromised.
The incident appears to have involved abuse of an authorized government email environment rather than a breach of Revolut itself. Because the requests carried valid domain authentication, they passed the technical indicators ordinarily used to establish that correspondence originated from the government organization.
Revolut declined to identify the government agency or department involved while investigations remain ongoing. The company also did not provide the exact number of affected customers, but characterized the impacted group as very limited.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators,” the Revolut spokesperson told CyberInsider. “Revolut systems and customer funds are unaffected.”
The company added that it has contacted impacted customers directly and is providing support.
Those receiving a notification should be especially cautious about targeted phishing, identity theft, SIM-swapping attempts, or scams referencing legitimate account information. Because identity documents, contact details, and transaction histories may have been exposed, affected users should independently verify unexpected communications claiming to come from Revolut, government agencies, or financial institutions and monitor their accounts for suspicious activity.







Leave a Reply