Revolut has confirmed a serious security incident in which an unauthorized party submitted fraudulent data requests using a legitimate government-agency email domain. The company says only a very limited number of customers were affected and that customer funds and core systems were not compromised, while later reports indicate that exposed information may have included identity documents, addresses and transaction records.
European fintech giant Revolut has confirmed a highly unusual data-security incident in which attackers did not need to break directly into its core banking systems. Instead, they used what the company described as a sophisticated external impersonation scam to submit fraudulent requests for customer information through a legitimate government-agency domain.
The requests appeared legitimate enough to be processed by Revolut employees.
The company later identified the activity, blocked the address and notified law enforcement, regulators and the relevant government agency.
This was not a conventional hack

The key detail is how the attackers obtained the information.
According to Revolut, the attackers did not simply compromise the company’s central systems and download a customer database.
Instead, they submitted fraudulent information requests through an authentic government domain.
The requests passed technical authentication checks and were treated as legitimate legal demands, according to reporting on the incident.
That makes the case particularly significant for cybersecurity teams.
Even strong technical defenses can be undermined when an attacker successfully convinces an employee that a fraudulent request is legitimate.
What customer data may have been exposed?
Reports based on notifications sent to affected customers say the potentially exposed information may have included names, dates of birth, postal addresses, email addresses, phone numbers and copies of identity documents, including passports and driver’s licenses.
Other reports mention verification selfies, account statements, IBANs and transaction histories, with some records potentially including Bitcoin activity.
There is an important caveat.
Revolut has not publicly confirmed that every one of these categories was exposed for every affected customer.
The company has described the affected group only as a “very limited” number of customers and has not publicly disclosed an official figure.
The Financial Times has separately reported that 680 customers were affected, but that number has not been publicly confirmed by Revolut.
Customer money was not compromised
Revolut has emphasized that customer funds and its systems remain unaffected.
The company said it immediately blocked the address involved and alerted the relevant government agency, law enforcement, data-protection authorities and financial regulators.
This means the incident is primarily about data exposure, rather than attackers gaining control of customers’ bank accounts.
But exposed personal information can still be extremely valuable to criminals.
A passport copy combined with a phone number, address and financial information can be used to create highly convincing phishing attempts or identity-fraud campaigns.
The danger may continue after the breach is contained
Blocking the fraudulent email address does not automatically erase information that may already have been disclosed.
Attackers can potentially use legitimate customer information to create much more convincing scams.
Instead of receiving a generic message asking for banking details, a victim could receive a call from someone who already knows their name, address, phone number and information about their financial relationship.
That can make social-engineering attacks much harder to recognize.
Affected customers should therefore be especially cautious about unexpected calls, emails and messages requesting passwords, verification codes or money transfers.
Why using a real government domain matters

The incident highlights a growing cybersecurity problem.
Many organizations verify whether an email comes from a legitimate domain and whether it passes technical authentication checks.
But those checks do not necessarily prove that the person using the channel is actually authorized to make the request.
In this case, according to Revolut, the attackers used a legitimate government domain, allowing their requests to appear genuine.
This is a classic example of increasingly sophisticated social engineering.
Instead of breaking through the security wall, the attacker tries to convince someone inside the organization to open the door.
The incident comes at a critical moment for Revolut
The breach comes as Revolut continues to expand rapidly.
The fintech has more than 80 million customers worldwide and is pushing aggressively into new markets. Earlier this month, the company received conditional approval for a U.S. national banking charter and is targeting the launch of its American bank in 2027.
That makes customer-data security increasingly important.
The incident could raise questions not only about cybersecurity but also about how financial institutions verify official requests for sensitive customer information.
What should Revolut customers do?
Anyone who receives a direct notification from Revolut that their account was affected should take it seriously and remain especially alert to suspicious communications.
Users should never provide:
OTP codes, passwords, card details, money transfers or access to their devices in response to an unsolicited message or call.
Attackers with genuine information about a customer can make phishing attempts look far more convincing than ordinary scams.
If someone claims to be from Revolut and asks for sensitive information, customers should contact the company through official channels inside the Revolut app, rather than using a phone number or link supplied by the caller.
The investigation is still underway
Revolut says it has notified the appropriate authorities and is cooperating with investigations.
The company has also said it has taken measures to prevent the incident from happening again.
But major questions remain: How were the requests verified? How long did the scheme operate? How much data was actually disclosed? And who was behind it?
Those answers will determine the ultimate scale of the incident.
For now, the clearest lesson is this:
Revolut was not breached by an attacker simply breaking into its systems. It was manipulated into handing sensitive information to an unauthorized party.
And that may be the most important cybersecurity warning in this case.
