British fintech Revolut confirmed it disclosed sensitive customer information to an unauthorized third party through fraudulent requests sent from a spoofed government agency email domain.
The exposed data included identity documents (passports, driver's licenses), birth dates, postal addresses, email addresses, phone numbers, verification selfies, account statements and transaction histories. Revolut said a limited number of customers were affected but did not disclose the exact count, specify which government agency was impersonated, or confirm whether the breach was geographically confined.
After discovering the incident, Revolut blocked the unauthorized email address and notified law enforcement and financial regulators. A company spokesperson confirmed that Revolut's systems and customer funds remained unaffected.
Security researcher ZachXBT noted the incident appeared to target high-net-worth users. Revolut operates as a bank in over 30 countries and serves more than 80 million customers globally, with recent market expansions in India, Mexico, France and the United Arab Emirates.
The breach timing complicates Revolut's near-term capital plans. The company is reportedly weighing a public listing that could value it at up to $200 billion—more than double its $75 billion private valuation from November. The U.S. Office of the Comptroller of the Currency granted conditional approval for Revolut to establish a national bank, with a planned launch in the first half of 2027. Any IPO would require regulatory clearance from the Financial Conduct Authority in the UK and comparable bodies in other markets where Revolut operates.
