The exposed information included customers’ names, birth dates, addresses, phone numbers, and copies of identity documents such as passports and driver’s licenses. Verification selfies, account statements, and transaction histories may also have been affected. Revolut said a limited number of customers were impacted and that it had contacted them directly, though it declined to share the exact number affected, the market involved, or which government agency was impersonated. The company blocked the fraudulent email address once it uncovered the scam and reported the incident to the relevant government agency, law enforcement, and financial regulators.
A Revolut spokesperson commented:
“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information. Revolut systems and customer funds are unaffected.”
Crypto security researcher ZachXBT flagged the breach notification publicly, noting that the incident appeared to target high-net-worth users specifically.
Revolut serves more than 80 million customers across over 30 countries and has been expanding into markets including India, Mexico, and the UAE. The company recently secured conditional approval to launch a national bank in the US, with plans to go live in the first half of 2027. It’s also said to be weighing a future public listing that could value the fintech at up to $200 billion.
