Revolut Confirms Limited Customer Data Breach
Revolut says a limited number of customers had sensitive data exposed after fake requests arrived from a legitimate government email domain.

Revolut has confirmed a customer data breach after a fraudster used a legitimate government email domain to send fake information requests. The British fintech says a limited number of customers were affected, but it has not said exactly how many — a detail that makes the word “limited” do a lot of heavy lifting.
According to TechCrunch, the exposed information may have included customers’ names and contact details, birth dates, postal and email addresses, phone numbers, passports, driving licences, verification selfies, account statements and transaction histories. Revolut said it contacted affected customers directly.
What's actually going on
Revolut told TechCrunch that an unauthorised third party submitted fraudulent requests using a legitimate government agency email domain. The company said it blocked the email address after discovering the scam, then alerted the relevant government agency, law enforcement and financial regulators.
The fintech said its systems and customer funds were unaffected. However, the incident concerns information that can still be valuable to criminals: identity documents, contact details and account records can support impersonation or targeted fraud even when nobody gets direct access to a bank balance.
Revolut declined to identify the government agency involved or say whether the incident was confined to one market. It also did not disclose the number of affected customers. TechCrunch reports that Revolut has more than 80 million customers worldwide and operates as a bank in more than 30 countries.
Why you should care
This was not described as a hack of Revolut’s core systems. It was an impersonation scam that abused trust in an official-looking channel — more con artist in a suit than digital battering ram. That distinction matters, but it does not make the outcome harmless: a genuine government domain helped a fake request look legitimate.
Customers who receive messages about this incident should use Revolut’s official app or website rather than clicking links in follow-up emails. The combination of identity documents, phone numbers and transaction information can make convincing phishing attempts much easier, so expect opportunists to try to turn this breach into the next scam.
Our opinion
Revolut deserves credit for notifying affected customers, blocking the address and involving regulators and law enforcement. But “limited” without a number is thin reassurance, especially when the exposed material may include passports, driving licences and financial histories. The real failure here was not merely technical; it was a trust process that treated an official domain as proof of authenticity.
Revolut customers should be alert for targeted follow-up scams, while the company should publish a clearer account of the scope and safeguards once investigations allow it. Until then, this is a serious privacy incident wrapped in carefully measured language — and customers are right to want more detail.