VMTech
Discuss a project

Revolut confirms customer data disclosure in impersonation scam

Revolut confirms customer data disclosure in impersonation scam

Revolut has confirmed that it disclosed sensitive customer information to an unauthorised third party after receiving fraudulent information requests sent from an email address using a legitimate government agency domain. The London-based fintech said a “limited” number of customers were affected, but did not disclose the number of individuals, the market involved or the agency whose domain was used.

A notification sent to affected customers said the disclosed information included identity and contact data such as dates of birth, postal and email addresses, and phone numbers. It also included copies of identity documents, including passports and driving licences. Revolut said verification selfies, account statements and transaction histories may also have been involved.

Fraudulent requests bypassed a trusted domain check

Revolut characterised the incident as a sophisticated external impersonation scam. An unauthorised party used a legitimate government agency email domain to submit fraudulent requests for information, creating an apparent basis for disclosure that the company later determined was illegitimate.

After identifying the scam, Revolut said it blocked the email address and notified the relevant government agency, law enforcement and regulators. The company also said it had contacted affected customers directly. Its spokesperson stated that Revolut’s systems and customer funds were unaffected.

Identity documents raise the impact of the incident

The scope described in the customer notice extends beyond basic contact information. Passport and driving-licence copies, verification selfies and transaction records are documents commonly used in identity verification processes. Their possible disclosure makes the event material for customers whose data was included, even though Revolut has not published a precise total.

Revolut has more than 80 million customers globally and operates as a bank in more than 30 countries. The company has recently expanded in India, Mexico, France and the UAE, while also advancing its banking footprint in Europe. Earlier this month, the US Office of the Comptroller of the Currency conditionally approved Revolut’s plans to establish a national bank, which the company expects to launch in the first half of 2027.

What businesses can take from the disclosure

The incident highlights the importance of treating an apparently credible sender domain as only one input in handling external data requests. Businesses processing sensitive identity records should ensure that requests are independently verified, escalation paths are clear and disclosures are limited to validated legal and operational requirements.

For organisations, the practical implication is to test request-verification controls against impersonation attempts that use trusted domains, while preparing customer-response procedures for incidents involving identity documents and financial records.

#cybersecurity#databreach#fintech#identitysecurity
Open analytics
On the site 0 views
min read 3 12.09.2026
Instagram

Revolut confirms customer data disclosure in impersonation scam

Open the post on Instagram ↗