
If you trust a fintech with your passport photo, your bank statements, and your daily spending habits, you probably assume the biggest risk is a hacker breaking in. Revolut’s latest incident is a reminder that the threat can come from a much simpler direction: someone just asking nicely with the right email address.
Revolut has confirmed to TechCrunch that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The company described it as a “sophisticated external impersonation scam,” which is a polished way of saying someone spoofed or compromised an official government email address and used it to submit fake data requests. Revolut complied. The data went out.
What was exposed is significant. According to a notification sent to affected customers and reviewed by TechCrunch, the leaked information potentially included names, birth dates, postal addresses, email addresses, and phone numbers. But it went further than that. Copies of identity documents, including passports and driver’s licenses, may have been handed over. So may verification selfies, account statements, and transaction histories. That is, in practical terms, nearly everything a fraudster would need to impersonate someone or target them for follow-on attacks.
Revolut has not said how many customers were affected, only describing the number as “limited.” It also declined to identify which government agency was impersonated or whether the incident was confined to a specific country. For a company with more than 80 million customers across 30-plus countries, vague disclosures like these do not inspire confidence. Affected customers were contacted directly, the company said.
Crypto security researcher ZachXBT flagged the incident publicly after Revolut’s notification email circulated online. The researcher suggested the attack appeared to be targeted at high-net-worth users, which, if accurate, would explain the narrow scope. Sophisticated, targeted fraud is harder to detect than bulk attacks, and the use of a legitimate government domain makes it harder still. Still, that Revolut’s compliance processes did not catch the discrepancy before data was disclosed is a real problem worth examining.
The timing is awkward for Revolut. The London-based company is reportedly weighing a public listing that could value it at up to $200 billion, a dramatic jump from its $75 billion private valuation late last year. It also recently received conditional approval from the U.S. Office of the Comptroller of the Currency to set up a national bank in America, with a planned launch in the first half of 2027. Alongside that, it has been expanding in India, Mexico, France, and the UAE, and secured banking licenses in both France and the UK.
All of which means Revolut is in the middle of a push to be taken seriously as a real bank, not just a fintech app. Real banks are expected to have airtight processes for responding to government data requests, including verification checks that go beyond trusting an email domain. This incident raises a direct question: what safeguards does Revolut have in place to verify the authenticity of legal requests for customer data, and did those safeguards fail here or simply not exist?
The company says its systems and customer funds are unaffected, and that it has blocked the offending email address while alerting law enforcement and regulators. But the data is out. For the customers whose passports and bank records are now in unknown hands, that assurance counts for very little.