Revolut disclosed sensitive customer information to scammers who impersonated a government agency, the financial technology company has confirmed. The attackers reportedly used an email address on a legitimate government domain to submit fraudulent data requests.
The exposed information may include identity documents, verification selfies and complete transaction histories. However, Revolut said the incident affected only a limited number of customers.
Scammers Used a Legitimate Government Email Address
Revolut described the incident as a sophisticated external impersonation scam. The attackers submitted information requests from an authentic email address belonging to an unnamed government agency.
Consequently, the requests appeared legitimate to the company. Revolut then provided customer information to the scammers without recognising that they lacked proper authorisation.
The company has not identified the government agency involved. It also remains unclear how the attackers gained access to its email system.
After discovering the scam, Revolut blocked the compromised address. It also alerted the affected agency, law enforcement bodies, data protection authorities and financial regulators.
Exposed Data Included Identity Documents
Reports indicate that the disclosed Revolut customer data included names, dates of birth and occupations. Postal addresses, email addresses and telephone numbers were also affected.
More sensitive records reportedly included copies of passports and driving licences. Furthermore, some customers may have had their verification selfies, account statements and transaction histories exposed.
Separate reporting suggests that the information also contained IBANs, cash withdrawal records and Bitcoin transactions. However, Revolut has not publicly confirmed every category of compromised data.
Such information could help criminals conduct identity theft, targeted phishing or financial fraud. Transaction records may also reveal where customers shop, travel and transfer money.
Revolut Says Only a Limited Number of Customers Were Affected
Revolut has not disclosed the exact number of people affected by the incident. Nevertheless, a company spokesperson said the scam involved a limited number of customers.
The company contacted those individuals directly after discovering the unauthorised disclosures. One affected customer publicly criticised the incident after recently receiving a separate request to provide extensive account information.
Revolut stressed that attackers did not compromise its internal systems. It also said customer funds remained safe.
Therefore, the incident appears to involve fraudulent information requests rather than a direct intrusion into Revolut’s infrastructure.
Previous Data Sale Claim Remains Unverified
The impersonation scam follows a separate allegation involving Revolut customer data. In July 2026, an attacker claimed to be selling information belonging to 75 million customers.
The advertised database allegedly contained names, addresses, phone numbers, email addresses and payment card details. Device information and hashed account credentials were also listed.
However, Revolut said it found no evidence that attackers had breached its systems. Security researchers later assessed that the collection probably combined information from several unrelated sources.
That earlier claim appears separate from the newly confirmed disclosure. Revolut serves more than 80 million retail customers and approximately 800,000 business clients worldwide.


0 responses to “Revolut Gave Customer Data to Government Impersonators”