Posted

Revolut confirmed a leak of customers’ personal data after fake requests made in the name of a government agency

British fintech company Revolut, which provides online banking services, confirmed that sensitive data belonging to some of its customers was disclosed to an unauthorized third party. A company spokesperson told Reuters on Saturday.

According to the spokesperson, the company received fraudulent requests sent from the domain of an official government agency. After detecting the incident, Revolut immediately blocked the sender’s address and notified the relevant government body, law enforcement agencies, data protection regulators, and financial supervisors.

“Revolut systems and customer funds are unaffected,” the spokesperson said. The company did not disclose the exact number of customers affected, saying only that a limited group of people was involved. Those affected were sent notifications.

According to TechCrunch, cited by Reuters, the disclosed information included dates of birth, postal and email addresses, phone numbers, and copies of identity documents such as passports and driver’s licenses. Other sources citing letters sent to customers also mention verification selfies, account statements, IBANs, and transaction histories, including bitcoin transactions. Facial biometric templates were not disclosed, according to the company.

Revolut described the incident as a “sophisticated external impersonation scam.” The company did not say which agency appeared in the emails or whether the incident was limited to a single market.

Revolut is one of Europe’s largest neobanks and has no physical branches. The company is preparing for a potential IPO and is targeting a valuation of up to $200 billion.

Customers are advised to treat emails and phone calls with caution, not to share data in response to requests outside the official app, and, if in doubt, to contact support through the Revolut app.