Revolut Confirms Data Breach via Government Impersonation Scam
Share
Revolut has confirmed a data breach affecting a limited number of customers following a sophisticated impersonation scam. The unauthorised third party used legitimate government agency email domains to submit fraudulent requests for information, which were subsequently fulfilled by Revolut employees as part of standard legal compliance procedures.
The fintech company stated that the requests carried valid technical domain authentication, allowing the attackers to bypass standard verification. While Revolut has maintained that its internal systems and customer funds remain untouched, the nature of the exposed data presents a significant risk to those affected.
Extensive Identity Data Exposed
Security researcher ZachXBT, who initially raised alarms regarding the incident, indicated that the compromised information goes far beyond basic contact details. According to the researcher, the exposed records include full names, dates of birth, residential addresses, phone numbers, and email addresses.
More critically, the breach reportedly included highly sensitive documents used for identity verification, such as copies of passports, driver’s licenses, and biometric verification selfies. The exposure may also extend to financial data, including IBANs, account-opening dates, complete transaction and withdrawal histories, and Bitcoin wallet reference numbers.
Muhammad Yahya Patel, a cybersecurity advisor at Huntress, noted that for a financial institution built on digital identity verification, the security controls for third-party data requests should be exceptionally rigorous. Patel described the collection of compromised information as a “complete identity theft kit” handed to the threat actors.
Mitigation and Response
Revolut confirmed that its security team immediately blocked the fraudulent email addresses upon detection. The company has also notified the affected customers and alerted relevant government agencies, law enforcement, data protection authorities, and financial regulators.
Cybersecurity experts have advised affected users to remain hyper-vigilant against highly targeted phishing attacks. Customers should be cautious of unexpected communications claiming to be from Revolut or government bodies and should never disclose passwords, passcodes, or one-time security codes through unsolicited messages.




Leave a Reply