British fintech Revolut confirmed it disclosed sensitive customer information to an unauthorized third party through fraudulent requests made from a legitimate government agency email domain. The compromised data included birth dates, postal addresses, email and phone numbers, as well as copies of passports and driver's licenses. Verification selfies, account statements and transaction histories were also exposed.

Revolut said the number of affected customers was limited but declined to disclose an exact figure. Crypto security researcher ZachXBT suggested the incident appeared to target high net worth users. The company said its systems and customer funds remained unaffected.

Revolut has notified impacted customers, blocked the email address used by the unauthorized party and alerted law enforcement and financial regulators. The timing is delicate: the U.S. Office of the Comptroller of the Currency granted conditional approval for Revolut to establish a national bank, with launch expected in the first half of 2027.

The fintech is also reportedly weighing an IPO that could value the company at up to $200 billion, up from its $75 billion private valuation in November. It operates as a bank in more than 30 countries and serves 80 million customers globally.

For a financial services company pursuing banking licenses and public markets access, data breaches involving identity documents create regulatory friction. Regulators evaluating new banking charters and institutional investors weighing an IPO both scrutinize operational security as a core competitive asset in a business built on customer trust.