Revolut notifies users after impersonation data breach
Revolut notified a subset of users that a third party posing as a government agency obtained names, identity documents, verification selfies, IBANs and full transaction histories.
London-based Revolut notified a subset of customers late last week that a third party posing as a government agency obtained personal and financial information. Exposed records included names, addresses, phone numbers, email addresses, dates of birth, occupations, copies of passports and driver’s licenses, verification selfies, IBANs, account statements, withdrawal records and full transaction histories, including Bitcoin activity.
The firm says the request carried valid technical domain credentials and used a legitimate government agency domain email. The submission was treated as an authentic agency inquiry, a type of request financial institutions are required to respond to when it appears to come from law enforcement or an official body.
Revolut blocked the attacker’s email address after discovering the incident and notified the relevant government agency, enforcement bodies, data protection authorities and financial regulators. The company contacted affected users directly and offered support to those reached.
Revolut did not disclose how many customers were affected and has not provided a timeline for any ongoing investigations. The company has not indicated whether any of the exposed financial information has been used fraudulently. Revolut also reports that its core systems and customer funds were not compromised.
In a statement, Revolut wrote: “Revolut recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information. Revolut systems and customer funds are unaffected. We have contacted the limited number of impacted individuals directly to inform them and provide support.”
The incident reflects a pattern of targeted social-engineering attacks on financial services in which attackers impersonate authorities or present convincing technical credentials and paperwork to bypass verification and legal-request checks.







